PUMAKIT is a sophisticated multi-stage Linux rootkit framework comprising a dropper, memory-resident executables, the PUMA loadable-kernel-module rootkit, and the Kitsune user-space shared-object rootkit. Its deployment chain executes embedded ELF payloads directly from anonymous memory using Linux memory-backed file mechanisms, reducing filesystem artifacts. The loader masquerades as legitimate system processes, checks host and kernel compatibility conditions, and loads the kernel component when prerequisites are satisfied.
PUMA uses direct system-call table hooks and ftrace-based hooks to conceal files, directories, processes, and its own presence from system tools. It can elevate the privileges of a calling process to root, evade debugging, alter system behavior, and execute userland commands from kernel threads masquerading as legitimate kernel activity. Its user-space Kitsune component provides additional concealment and persistence through dynamic-linker preloading. PUMAKIT also includes command-and-control functionality. Earlier related iterations have been identified as Facefish, Kitsune, and Megatsune. The malware targets Linux systems; no initial-access or delivery vector is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PUMAKIT, a kernel rootkit to escalate privileges, hide files and directories, and conceal itself from system tools, along with prior iterations known as Facefish (February 2021), Kitsune (February 2022), and Megatsune (November 2023).
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“A rootkit can ask the kernel’s ftrace machinery to do it on its behalf; essentially ‘legitimizing’ the hook.” | “By overwriting a pointer in this table, an attacker can redirect a legitimate syscall, such as getdents64, kill, or read, to a malicious handler.” | “Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.”
"possibly masquerading as a legitimate process (like cron)"; the rootkit loader "attempts to hide itself by mimicking it as the /usr/sbin/sshd executable."
"After running through all of the items in the script, the /tmp/vmlinux and /tmp/script.sh files are deleted."
"The rootkit loader attempts to hide itself... It checks for particular prerequisites, such as whether secure boot is enabled and the required symbols are available."
This empowers a rootkit to filter the output of the ls command to hide malicious files or prevent a specific process from being terminated.
"The SO is referred to as Kitsune" and "manipulates user-space interactions via LD_PRELOAD"; the configuration includes "LD_PRELOAD=/lib64/libs.so."
The temporary script "inspects files using the file command" and searches /boot/vmlinuz to locate compressed portions and produce /tmp/vmlinux.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux rootkit discussed for masquerading and spawning kernel threads to execute userland commands through kthreadd.
Linux rootkit that masquerades activity through kernel threads and executes userland shell commands via kthreadd.
Linux rootkit described as combining direct syscall-table hooking with ftrace-based hooks for layered concealment and interception.
Linux kernel rootkit described as combining syscall-table hooking with ftrace-based hooks for layered interception and stealth.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.