logo

Detection primitives for eBPF rootkits

ID: 5fca4fce-feae-5f46-a6c1-77c452556fd6

STIX ID: report--5fca4fce-feae-5f46-a6c1-77c452556fd6

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

...
...

This report analyzes real-world Linux eBPF rootkits (VoidLink, LinkPro, Atomic Arch), describing how they abuse rare eBPF helpers (bpf_probe_write_user, bpf_override_return, bpf_send_signal) and kprobes/tracepoints to hide network sockets, conceal eBPF programs from enumeration, and kill debuggers; it explains the kernel mechanics behind each technique and presents a reliable defensive approach of capturing load-time eBPF fingerprints (program type, helper bitmap, metadata) to detect such rootkits before they can attach and evade inspection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.