logo

New stealthy Pumakit Linux rootkit malware spotted in the wild

ID: f8d6d739-fbf4-5282-b5ca-94ceb2913cd3

STIX ID: report--f8d6d739-fbf4-5282-b5ca-94ceb2913cd3

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-12

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Elastic Security details Pumakit, a sophisticated Linux rootkit campaign composed of a memory-resident dropper, an LKM kernel module (puma.ko) and a userland shared object (Kitsune SO). The malware conditionally activates on older kernels (pre-5.7), leverages kallsyms_lookup_name and ftrace to hook syscalls and abuse prepare_creds/commit_creds for stealthy privilege escalation, hides files/processes/network artifacts, and communicates with a C2; Elastic published YARA rules and file hashes to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.