New stealthy Pumakit Linux rootkit malware spotted in the wild
ID: f8d6d739-fbf4-5282-b5ca-94ceb2913cd3
STIX ID: report--f8d6d739-fbf4-5282-b5ca-94ceb2913cd3
Feed Name: Bleeping Computer
Elastic Security details Pumakit, a sophisticated Linux rootkit campaign composed of a memory-resident dropper, an LKM kernel module (puma.ko) and a userland shared object (Kitsune SO). The malware conditionally activates on older kernels (pre-5.7), leverages kallsyms_lookup_name and ftrace to hook syscalls and abuse prepare_creds/commit_creds for stealthy privilege escalation, hides files/processes/network artifacts, and communicates with a C2; Elastic published YARA rules and file hashes to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
