LinkPro is a previously undocumented GNU/Linux eBPF-based backdoor with rootkit characteristics, written in Go and observed in a compromise of AWS-hosted Linux infrastructure, including Kubernetes and Amazon EKS environments. It was deployed late in a broader intrusion that began with exploitation of CVE-2024-23897 on an exposed Jenkins server and expanded through malicious container deployment and credential harvesting from cluster and host resources. No formal attribution has been established, but the activity has been assessed as financially motivated.
LinkPro combines covert remote access, persistence, and stealth. It supports two communication models: a passive reverse mode in which command handling is activated only after receipt of a specially crafted magic packet, and an active forward mode in which it initiates outbound command-and-control communications. In passive mode, it installs XDP and TC eBPF programs that implement a port-knocking style trigger using a TCP SYN packet with a distinctive window size, then transparently rewrites packet ports so the real listening service remains concealed. This design complicates host- and network-level detection and supports covert operator access.
Its operator functionality includes interactive shell access, arbitrary command execution, file management, file upload and download, file exfiltration, proxying through SOCKS5-style tunneling, and runtime configuration such as sleep and jitter. These features make it suitable for post-compromise persistence, internal pivoting, and data theft.
For stealth, LinkPro uses an eBPF hide module to conceal files, processes, and some of its own BPF artifacts. It hooks directory enumeration paths and interferes with BPF object enumeration so defensive tooling may stop listing programs prematurely, reducing visibility in tools such as bpftool and libbpf-based utilities. When kernel support for its eBPF concealment is unavailable, LinkPro falls back to a user-space hiding mechanism based on LD_PRELOAD, using a malicious shared library to suppress selected files, processes, and network-port visibility from common user-space tools.
Persistence is achieved by masquerading as a legitimate-looking system service and enabling itself through systemd. It also timestomps persistence artifacts to blend with normal system files. An embedded kernel module has been identified in samples, although it was not observed being used operationally in the documented intrusion.
LinkPro exemplifies the increasing operational use of eBPF for Linux malware stealth. Its combination of kernel-assisted concealment, covert activation, persistence, proxying, and remote shell capability makes it a high-end Linux backdoor/rootkit suited to long-term access on cloud and containerized infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Forensic analysis identified a vulnerable Jenkins server (CVE-2024–23897) exposed on the internet as the source of the compromise. The latter served as the initial access for the threat actor...
18 distinct techniques documented for this family, organized by ATT&CK tactic.
LinkPro executes commands via /bin/sh -c ( shell command) and provides a full interactive shell with /bin/bash ( terminal_create command).
bpf_override_return() replaces the return value of a kernel function from inside an eBPF program... To user space, it looks as though the kernel itself produced that result.
Uses /etc/ld.so.preload as an alternative/fallback concealment mechanism.
LinkPro uses bpf_override_return() to hide its own eBPF programs from enumeration... On a match, it calls bpf_override_return(ctx, -ENOENT). The caller (bpftool, libbpf, or anything else walking the program list) sees -ENOENT and concludes there are no more entries.
Uses eBPF hooks on getdents and sys_bpf to hide its artifacts at the kernel level.
Data exfiltrated via download_manage is Base64-encoded. C2 traffic is XOR-encrypted.
The malware masquerades as systemd-resolved by using the filenames /usr/lib/.system/.tmp~data.resolveld and systemd-resolveld.service .
LinkPro modifies the timestamps of its persistence files to match a legitimate system file (e.g., /etc/passwd ).
The "magic packet" concept (TCP SYN with a window of 54321) is a form of traffic signaling to activate the passive C2.
VoidLink needs to hide connections on a specific port, a standard rootkit feature.
bpf_override_return() replaces the return value of a kernel function from inside an eBPF program... To user space, it looks as though the kernel itself produced that result.
Uses /etc/ld.so.preload as an alternative/fallback concealment mechanism.
LinkPro uses bpf_override_return() to hide its own eBPF programs from enumeration... On a match, it calls bpf_override_return(ctx, -ENOENT). The caller (bpftool, libbpf, or anything else walking the program list) sees -ENOENT and concludes there are no more entries.
Uses HTTP and DNS (via DNS Tunneling T1071.004 ) for its C2 communications, in addition to raw TCP/UDP.
The reverse_connect command sets up a SOCKS5 proxy tunnel to relay traffic, serving as a pivot.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux eBPF rootkit whose Hide module intercepts BPF enumeration commands and uses bpf_override_return(ctx, -ENOENT) to truncate bpftool/libbpf listings, concealing its own eBPF programs from defenders.
LinkPro is an eBPF-based rootkit, designed to provide stealthy persistence and control over infected systems at the kernel level.
LinkPro is a stealthy GNU/Linux rootkit and backdoor written in Golang. It uses eBPF modules and userland hooks to conceal its presence, can be remotely activated via a magic packet, and supports multiple C2 communication protocols. It provides attackers with persistent, covert access, command execution, file operations, and proxy tunneling capabilities.
LinkPro is a Linux rootkit based on eBPF, found deployed on compromised AWS infrastructure to provide stealthy persistence and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.