Boopkit is a 2022 Linux eBPF-based backdoor proof of concept. It uses eBPF socket-buffer manipulation to establish a covert command-and-control channel embedded in crafted network packets, avoiding a conventional loadable kernel module. Boopkit exemplifies the use of privileged eBPF programs for stealthy kernel-resident functionality that may evade module-focused rootkit inspection because eBPF programs are not represented as kernel modules. It runs on Linux and requires privileges sufficient to load and attach eBPF programs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
“An attacker can load one or more eBPF programs that attach to sensitive kernel events... [including] the system call entry for execve.” | “Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux eBPF backdoor discussed as triggering detection based on suspicious use of the bpf_probe_write_user helper.
Linux eBPF backdoor cited as a true-positive example for detection of bpf_probe_write_user helper use.
Linux eBPF-based rootkit/implant that uses eBPF to create a covert C2 channel embedded in crafted network packets, enabling stealthy control without a traditional kernel module.
Proof-of-concept eBPF-based Linux rootkit/backdoor that uses eBPF programs and socket-buffer manipulation to provide covert command-and-control communications through crafted packets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.