logo

Linux rootkits explained – Part 2: Loadable kernel modules

ID: 0a82f5dc-5d21-50f8-9917-63930b8e69e6

STIX ID: report--0a82f5dc-5d21-50f8-9917-63930b8e69e6

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2023-10-24

Date Updated: 2026-05-01

...
...

This Wiz Research blog post explains Linux Loadable Kernel Module (LKM) rootkits: what LKMs are, how attackers hook kernel functions (syscall table, kprobes, ftrace, VFS), real-world examples and actors (e.g., Diamorphine, Reptile, adore-ng, Syslogk, TeamTNT, Winnti), a demo showing hiding files via a getdents hook, and practical detection and mitigation recommendations (avoid privileged containers, use AppArmor/SELinux, secure boot).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.