eBPF Rootkit Targeting AWS and Linux Environments (Campaign)
ID: 0e85f419-dfdc-5b27-8fe9-fb0866618d42
STIX ID: report--0e85f419-dfdc-5b27-8fe9-fb0866618d42
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-10-14
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
This report describes a sophisticated intrusion where attackers exploited CVE-2024-238976 on a Jenkins server to move into AWS EKS clusters, deploy a malicious Docker image (kvlnt/vv) that installed a Rust downloader and an encrypted vShell backdoor, and subsequently installed the LinkPro rootkit (Golang) on Linux hosts. LinkPro uses eBPF modules (Hide and Knock) to conceal artifacts and activate on TCP "magic packets," falls back to LD_PRELOAD when eBPF is unavailable, achieves persistence by impersonating systemd-resolved, and provides remote shell, SOCKS5 proxying, and DNS/HTTP C2, indicating a highly adaptive and operationally mature financial-motivated campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
