Declawing PUMAKIT
ID: 9ad30f17-db01-53a5-b615-831b06d06a1f
STIX ID: report--9ad30f17-db01-53a5-b615-831b06d06a1f
Feed Name: Elastic Security Labs
PUMAKIT is a sophisticated multi-stage Linux malware family that uses a fileless dropper to load memory-resident executables, deploy an LKM rootkit (PUMA) that hooks ~18 syscalls via ftrace, and a userland shared object (Kitsune) to achieve stealth, persistence, and privilege escalation (notably via an rmdir()-based command channel). The report includes code-level analysis, example commands demonstrating hiding and root escalation, IOC listings (SHA256s, domains, IP), and practical detection/mitigation artifacts such as EQL/KQL queries and a YARA rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
