logo

On Drovorub: Linux Kernel Security Best Practices

ID: 2db03700-31bd-57a3-aa5e-d02d26e11beb

STIX ID: report--2db03700-31bd-57a3-aa5e-d02d26e11beb

Feed Name: McAfee Labs Blog

Threat Score
80/100

Date Published: 2020-08-13

Date Updated: 2026-04-28

Author: ATR Operational Intelligence Team

...
...

McAfee summarizes the NSA/FBI advisory on Drovorub, a Linux kernel rootkit attributed to APT28, outlining that older kernels (<= 3.7) without module-signing enforcement are vulnerable, describing detection challenges and suggested forensic techniques (rootkit scanners, Volatility), and recommending mitigations including UEFI Secure Boot, kernel module signing, Linux Lockdown, sysctl hardening, and enabling SELinux/AppArmor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.