Malware trends: eBPF exploitation, malware configurations stored in unexpected places, and increased use of custom post-exploitation tools
ID: 5be13c9f-5c6e-5664-b193-4e7ff755599e
STIX ID: report--5be13c9f-5c6e-5664-b193-4e7ff755599e
Feed Name: Dr.Web News
Threat Score
**Doctor Web investigators identified an active Southeast Asia-focused campaign that leverages malicious eBPF programs to hide a kernel-module rootkit and install a remote access trojan; the trojan supports traffic-tunneling and retrieves configuration from public platforms (GitHub, blogs), enabling stealthy C2 communications and post-exploitation use.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
