Researchers detailed Symbiote, a Linux malware family built as a 64-bit ELF shared object that loads into running processes and uses extensive function hooking to evade detection. The malware intercepts multiple libc, PAM, and libpcap functions to hide files, processes, and TCP connections, while also filtering /proc network data to conceal selected ports and checking process names to suppress visibility of malware-related activity. BlackBerry described the threat as a nearly impossible-to-detect Linux implant because it operates parasitically inside other processes rather than as a standalone executable.
Analysis of an early Symbiote sample found that it specifically targets SSH and SCP credentials by intercepting authentication and read operations. The stolen data is encrypted with RC4, staged locally in a disguised file, and then exfiltrated through crafted DNS requests to an attacker-controlled domain, giving the malware both credential-theft and covert command-and-control capabilities. The reporting highlights Symbiote as a stealth-focused Linux threat that combines rootkit-style hiding techniques with credential harvesting and DNS-based data theft.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A technical report analyzed an apparent early development build of Symbiote, describing its libc, PAM, and libpcap-related hooks used to hide files, processes, and TCP connections while stealing SSH, SCP, and PAM credentials. The report also identified the sample hash, local staging file, RC4 keying, and DNS-based exfiltration domain.
A BlackBerry blog post introduced Symbiote as a new Linux malware threat that is difficult to detect. The reference anchors this disclosure to June 2022 through the source URL path.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.