LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
A new GNU/Linux rootkit named LinkPro has been discovered, which utilizes eBPF modules to hide its presence and enable remote activation. This finding emerged from an investigation into a compromised AWS-hosted infrastructure.
Linux
Read Full Original Article →