A sophisticated cyberattack targeted AWS-hosted infrastructure, specifically exploiting a vulnerable Jenkins server to gain initial access. The attackers leveraged CVE-2024-238976 to move laterally into AWS Elastic Kubernetes Service (EKS) clusters, where they deployed a malicious Docker image named kvlnt/vv. This image contained a Rust-based downloader, vGet, which was used to retrieve an encrypted vShell backdoor payload from an Amazon S3 bucket. The threat actors achieved persistence and escalated privileges by exploiting container escape vulnerabilities, particularly through host filesystem mounts. Once inside the environment, the attackers installed the LinkPro rootkit, a Golang-based malware designed for GNU/Linux systems. LinkPro embeds four ELF binaries, including two eBPF modules called 'Hide' and 'Knock', a shared library (libld.so), and an unused kernel module (arp_diag.ko). The Hide module uses tracepoint and kretprobe hooks on getdents and sys_bpf to conceal files, processes, and its own BPF maps, effectively evading detection by tools such as bpftool. The Knock module listens for specially crafted TCP 'magic packets' (SYN packets with a window size of 54321) to activate its command and control (C2) listener, redirecting traffic to a hidden port (2233) and bypassing firewalls and log monitoring. If eBPF is unavailable due to kernel restrictions, LinkPro falls back to using the LD_PRELOAD technique, installing a malicious shared library to hook libc functions and hide its presence in user space. Persistence is further maintained by masquerading as systemd-resolved, creating deceptive files and unit configurations to blend in with legitimate system processes. Once operational, LinkPro provides attackers with full remote shell access, file manipulation capabilities, SOCKS5 proxy tunneling, and DNS/HTTP-based C2 communications. The infection chain demonstrates advanced techniques for both initial compromise and stealthy long-term access, including the use of encrypted payloads, container escape, and kernel-level rootkit functionality. The campaign highlights the growing abuse of eBPF technology by threat actors to evade traditional security controls and maintain covert access to cloud and Linux environments. Indicators of compromise and YARA rules have been published to aid in detection and response. The incident underscores the importance of securing CI/CD pipelines, monitoring for unusual container activity, and hardening Linux kernel configurations against eBPF abuse. No definitive attribution has been made regarding the threat actors behind this campaign. The attack serves as a warning for organizations leveraging cloud-native technologies and underscores the need for robust monitoring and incident response capabilities.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
On October 14, 2025, Synacktiv published its investigation detailing the AWS compromise, the malware chain, and the LinkPro eBPF rootkit's concealment and activation mechanisms. Wiz also published a related incident entry the same day covering the eBPF rootkit targeting AWS and Linux environments.
The final payload identified was LinkPro, a Golang backdoor/rootkit for GNU/Linux that used eBPF for stealth and conditional activation via a magic packet. It supported reverse and forward connectivity, interactive shell access, file operations, and SOCKS5 pivoting while persisting as a fake systemd-resolved-like service.
Weeks after the initial compromise, investigators observed a new stage of malware activity, including a vShell dropper that used DNS tunneling. This marked an escalation beyond the earlier container-based access and payload delivery.
The malicious container executed a Rust downloader called vGet, which retrieved an encrypted vShell 4.9.3 payload from an S3 bucket for in-memory execution. Synacktiv observed vShell command-and-control traffic over WebSocket to 56.155.98.37.
After initial access, the threat actor deployed a malicious Docker image, kvlnt/vv, into multiple Amazon EKS clusters. The image enabled host access through a bind mount of the root filesystem and was used to establish persistence, proxying, and staging for follow-on payloads.
Synacktiv assessed that the compromise began when attackers exploited an internet-exposed Jenkins server vulnerable to CVE-2024-23897, gaining initial access to the AWS-hosted environment. This was the first identified entry point in the intrusion chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.