PwnKit is a self-contained local privilege-escalation exploit for CVE-2021-4034, a vulnerability in Polkit’s pkexec utility on Linux. Successful exploitation can allow a local, unprivileged attacker to obtain root privileges and execute arbitrary commands. It has been used by multiple intrusion clusters after initial access to elevate privileges on compromised Linux systems, including telecommunications and other high-value enterprise environments. PwnKit is an exploit tool rather than a standalone malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The domain-escalation toolkit included PwnKit (CVE-2021-4034).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The threat actor used PwnKit, a self-contained exploit for CVE-2021-4034.”
“Attackers deployed PwnKit, a self-contained exploit (CVE-2021-4034) to achieve local privilege escalation on Linux systems.”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit for the Polkit pkexec local privilege-escalation vulnerability, included in the actor's post-exploitation toolkit.
Local privilege escalation exploit for Linux (polkit pkexec) used to obtain root-level execution.
Local privilege escalation exploit for Polkit pkexec (CVE-2021-4034) used to obtain root on Linux systems.
A privilege-escalation exploit used to obtain root privileges and execute additional commands on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.