LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets Emmie Evans October 17, 2025

LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets

An investigation into the compromise of an Amazon Web Services (AWS)-hosted infrastructure has led to the discovery of a new GNU/Linux rootkit dubbed LinkPro, according to findings from Synacktiv.
“This backdoor features functionalities relying on the installation of two eBPF [extended Berkeley Packet Filter] modules, on the one hand to conceal itself, and on the other hand to be remotely

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top