KoviD is a Linux rootkit that uses ftrace-based kernel hooks. It has been included in public Linux rootkit datasets evaluating the limitations of static antivirus detection, where trivial non-functional binary modifications affected detection results. Its ftrace use reflects abuse of the Linux kernel tracing framework to intercept kernel activity for stealth-oriented rootkit functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux rootkit included in the static detection comparison, illustrating detection degradation after stripping or trivial modification.
Linux rootkit included in static-detection testing; stripping its binary sharply reduced antivirus detections.
Linux rootkit cited as abusing the kernel ftrace framework to install hooks.
Linux rootkit referenced as abusing ftrace to register kernel function hooks via legitimate tracing interfaces.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.