New Snapekit Rootkit Malware Targeting Arch Linux Users
ID: 130f0005-d38f-572f-9fe7-736d28d78752
STIX ID: report--130f0005-d38f-572f-9fe7-736d28d78752
Feed Name: cybersecurityNews.com
Snapekit is a newly reported, sophisticated rootkit targeting Arch Linux (kernel 6.10.2-arch1-1 on x86_64). The malware hooks 21 system calls and uses a user-space dropper with multiple anti-analysis protections — including sandbox, debugger and disassembler detection, ptrace checks, and code obfuscation — to evade detection and analysis; the author ('Humzak711') has indicated plans to open-source the project, which could broaden its impact. The report provides technical behavior and mitigation recommendations for researchers but does not include IOCs or evidence of active in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
