RST TI Report Digest: 31 Mar 2025
ID: e9bcad76-0b47-55b3-ac51-9eee0090a7a1
STIX ID: report--e9bcad76-0b47-55b3-ac51-9eee0090a7a1
Feed Name: RST Cloud Blog
Threat Score
**Shedding Zmiy deployed the PUMA Linux kernel rootkit and Bulldog backdoor in a covert campaign, leveraging kernel-level stealth, privilege escalation, and legitimate service manipulation to maintain persistence and remote control; activity was traced from August 2023 with escalation by November 2023 and many IoCs (IPs, domains, file hashes) provided for detection and response.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
