Snapekit is a Linux kernel rootkit that deploys a malicious loadable kernel module through a dedicated dropper. It is designed to maintain persistent, kernel-level access on compromised Linux systems and to evade host-based monitoring by concealing files, processes, and network activity. Snapekit uses process-name spoofing and masquerades activity as legitimate kernel-worker processes. It also exploits Linux capabilities to facilitate privilege escalation. Its kernel-module-based design provides stealthy, persistent unauthorized access and supports prolonged post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
T1547.006 Kernel Modules and Extensions is a technique in the MITRE ATT&CK framework under the Persistence tactic. It refers to the use of kernel modules in Linux (Loadable Kernel Modules, or LKMs) and kernel extensions in macOS (kexts) to extend the core functionality of the system’s kernel without requiring a reboot.
T1547.006 Kernel Modules and Extensions is a technique in the MITRE ATT&CK framework under the Persistence tactic. It refers to the use of kernel modules in Linux (Loadable Kernel Modules, or LKMs) and kernel extensions in macOS (kexts) to extend the core functionality of the system’s kernel without requiring a reboot.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux rootkit included in the static detection experiment demonstrating the fragility of static signatures.
Linux rootkit included in static-detection testing; antivirus detection was substantially reduced by stripping and by a one-byte modification.
Linux rootkit delivered via a specially crafted dropper that unpacks the snapekit.ko module into /lib/modules/ for kernel-level insertion. It uses obfuscation such as spoofing process names, masquerading as legitimate processes like kworker, and exploiting Linux capabilities to escalate privileges. Its objective is to hide files, processes, and network activity to maintain stealthy persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.