logo

PUMAKIT, a sophisticated rootkit that uses advanced stealth mechanisms 

ID: d37e3c39-f9c4-5eb3-9805-b0b81db3225b

STIX ID: report--d37e3c39-f9c4-5eb3-9805-b0b81db3225b

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2024-12-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

PUMAKIT is a sophisticated Linux loadable kernel module (LKM) rootkit analyzed by Elastic Security Lab that employs ftrace-based syscall and kernel-function hooking to hide files and processes, perform privilege escalation, and evade system tools and debugging. The report describes a multi-stage dropper and memory-resident components, a structured command interface processed via an intercepted rmdir syscall, support for older kernels via kallsyms_lookup_name usage, and provides detection resources including YARA rules for the dropper, loader, LKM, and associated shared objects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.