logo

eBPF Rootkit Targeting AWS and Linux Environments (Campaign)

ID: 0e85f419-dfdc-5b27-8fe9-fb0866618d42

STIX ID: report--0e85f419-dfdc-5b27-8fe9-fb0866618d42

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2025-10-14

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

This report describes a sophisticated intrusion where attackers exploited CVE-2024-238976 on a Jenkins server to move into AWS EKS clusters, deploy a malicious Docker image (kvlnt/vv) that installed a Rust downloader and an encrypted vShell backdoor, and subsequently installed the LinkPro rootkit (Golang) on Linux hosts. LinkPro uses eBPF modules (Hide and Knock) to conceal artifacts and activate on TCP "magic packets," falls back to LD_PRELOAD when eBPF is unavailable, achieves persistence by impersonating systemd-resolved, and provides remote shell, SOCKS5 proxying, and DNS/HTTP C2, indicating a highly adaptive and operationally mature financial-motivated campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.