logo

Malware trends: eBPF exploitation, malware configurations stored in unexpected places, and increased use of custom post-exploitation tools

ID: 5be13c9f-5c6e-5664-b193-4e7ff755599e

STIX ID: report--5be13c9f-5c6e-5664-b193-4e7ff755599e

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2024-12-10

Date Updated: 2026-04-27

...
...

**Doctor Web investigators identified an active Southeast Asia-focused campaign that leverages malicious eBPF programs to hide a kernel-module rootkit and install a remote access trojan; the trojan supports traffic-tunneling and retrieves configuration from public platforms (GitHub, blogs), enabling stealthy C2 communications and post-exploitation use.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.