Researchers detailed Syslogk, a Linux loadable-kernel-module rootkit that alters kernel execution paths to conceal malware. It inline-hooks proc_root_readdir to hide processes associated with was_sys_relay, tcp4_seq_show to remove selected listening ports from TCP socket listings, and VFS readdir operations to conceal files and directories containing was-patch. Syslogk also unlinks itself from kernel-module and sysfs listings, frustrating checks using lsmod and /sys/module; kernel-level investigation and remediation are required to restore visibility.
The activity reflects a broader Linux rootkit tradecraft pattern spanning user-space dynamic-linker hijacking through LD_PRELOAD, malicious kernel modules, ftrace and syscall hooks, and newer eBPF or io_uring-assisted techniques. Recent malware including PUMAKIT has combined memory-resident execution, an LKM rootkit, and an LD_PRELOAD shared object for persistence, stealth, privilege escalation, and command execution. Defenders should monitor sensitive linker and SSH configuration changes, suspicious shared objects and kernel modules, loaded eBPF programs, kernel-function and VFS-pointer integrity, tracing/probe activity, and anomalous web-server or system-account behavior.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
RingReaper was described as an experimental io_uring-based concept that can stealthily replace or mediate read, write, connect, and unlink-related operations.
A cron-masquerading PUMAKIT dropper was first uploaded to VirusTotal with zero detections. The sample's SHA-256 hash was 30b26707d5fb407ef39ebee37ded7edeea2890fb5ec1ebfa09a3b3edfc80db1f.
Boopkit demonstrated covert command-and-control communications using eBPF and socket-buffer manipulation.
TripleCross demonstrated rootkit functionality through eBPF programs attached to events including execve.
Azazel was identified in the Linux rootkit evolution discussion as a shared-object rootkit with optional kernel-mode features.
Jynx was documented as a Linux userland rootkit that hooks libc functions to hide files and network connections.
Analysis found that Syslogk inline-hooks process and TCP-enumeration functions and modifies VFS readdir handling to hide processes, ports, files, and its own kernel module. V3 Net for Linux Server reportedly detected the hidden module and restored visibility of previously hidden files after remediation.
Linux kernel 6.9 moved x86-64 syscall dispatch to a switch-based x64_sys_call dispatcher, so changes to sys_call_table entries no longer normally redirect syscall execution. The FlipSwitch technique was presented as patching call sites in the new dispatcher instead.
Threat hunting of VirusTotal samples identified PUMAKIT, a multi-stage Linux malware suite with memory-resident payloads, the PUMA LKM rootkit, and the Kitsune LD_PRELOAD user-space rootkit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceelastic.co
Open sourceman7.org
Open sourcearmosec.io
Open sourceelastic.co
Open sourceelastic.co
Open sourceintezer.com
Open sourcephrack.org
Open sourcephrack.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.