Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker remotely executes it on demand when a specially crafted TCP packet... is sent to the infected machine... These are known as magic packets because they have a special format and special powers.
Syslogk hides the LKM by removing its own module node from the kernel module list... As a result, Syslogk does not appear in the list of modules returned by the lsmod command. It also removes its own kobject node from /sys/module. | Syslogk modifies Linux kernel execution flow using inline hooking and VFS table hooking, and hides its own Loadable Kernel Module (LKM) from module lists and sysfs.
The attacker remotely executes it on demand when a specially crafted TCP packet... is sent to the infected machine... These are known as magic packets because they have a special format and special powers.
First, it checks whether the packet is a TCP packet and, in that case, it also checks the source port, which is expected to be 59318. Rekobee will be executed by the rootkit if the magic packet fits the mentioned criteria.
The attacker remotely executes it on demand when a specially crafted TCP packet... is sent to the infected machine, which inspects the traffic by installing a netfilter hook.
The proc_root_readdir function is hooked so that processes named “was_sys_relay,” and associated parent/child processes, are not returned when utilities such as ps, top, and pstree enumerate /proc. | Syslogk hooks tcp4_seq_show, which outputs TCP socket information from /proc/net/tcp, and removes output entries containing specific port numbers.
The threat actor performed hooking on the readdir function in the VFS table. If a file or directory name contains the string “was-patch,” the corresponding entry is not returned.
Port Knocking is a method where the malware opens a specific port on an infected system and goes on standby. When the threat actor sends a Magic Packet to the system, the received packet is used as a basis to establish a connection with the C&C server.
The attacker remotely executes it on demand when a specially crafted TCP packet... is sent to the infected machine... These are known as magic packets because they have a special format and special powers.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel rootkit that patches kernel execution paths through inline hooks on proc_root_readdir and tcp4_seq_show, and VFS readdir table hooking. It hides the was_sys_relay process and its descendants, TCP socket entries containing configured ports, files/directories containing “was-patch,” and its own LKM from lsmod and /sys/module.
Syslogk is a rootkit used by the threat actor for stealth and persistence on compromised systems.
Rootkit reported in June 2022 that is heavily based on adore-ng.
Linux rootkit referenced for its similarity to Reptile, notably port-knocking activation via Magic Packet and use of Rekoobe as a backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.