logo

Declawing PUMAKIT

ID: 9ad30f17-db01-53a5-b615-831b06d06a1f

STIX ID: report--9ad30f17-db01-53a5-b615-831b06d06a1f

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2024-12-12

Date Updated: 2026-04-27

...
...

PUMAKIT is a sophisticated multi-stage Linux malware family that uses a fileless dropper to load memory-resident executables, deploy an LKM rootkit (PUMA) that hooks ~18 syscalls via ftrace, and a userland shared object (Kitsune) to achieve stealth, persistence, and privilege escalation (notably via an rmdir()-based command channel). The report includes code-level analysis, example commands demonstrating hiding and root escalation, IOC listings (SHA256s, domains, IP), and practical detection/mitigation artifacts such as EQL/KQL queries and a YARA rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.