s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.linkpro

📛 Threat Title

Malware family: LinkPro

Category: LinkPro First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.linkpro`. Printable name: LinkPro.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.linkpro VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.linkpro

IOC database

Type
domain
Value
elf.linkpro
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.linkpro

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.linkpro

References (1)

Remediations (10)

  • web:cyberpress.org

    A newly uncovered Linux rootkit, dubbed LinkPro , leverages extended Berkeley Packet Filter (eBPF) technology to conceal its presence and maintain persistence on compromised systems. The Synacktiv CSIRT discovered the malware during an investigation of a breached AWS infrastructure.

  • web:cybersecuritynews.com

    LinkPro rootkit targets Linux systems using eBPF to hide processes, exploit Jenkins CVE-2024-23897, and backdoor AWS Kubernetes servers.

  • web:cybersixt.com

    LinkPro also delivered to Kubernetes nodes a second malware strain and a Golang-based rootkit; it can operate in passive or active mode and only listens for C2 commands after receiving a specific TCP packet, or can initiate contact directly.

  • web:gbhackers.com

    Security researchers from Synacktiv CSIRT have uncovered a sophisticated Linux rootkit dubbed LinkPro that leverages eBPF (extended Berkeley Packet Filter).

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.

  • web:rhyno.io

    Security researchers have uncovered a highly sophisticated new malware for Linux servers, dubbed LinkPro , that can remain almost completely invisible until activated by a secret signal. This rootkit, discovered during an investigation of a compromised Amazon Web Services (AWS) environment, uses advanced modern Linux features to hide its presence and give attackers a secret backdoor into ...

  • web:thehackernews.com

    Synacktiv uncovered LinkPro , a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.synacktiv.com

    LinkPro : eBPF rootkit analysis Introduction eBPF (extended Berkeley Packet Filter) is a technology adopted in Linux for its numerous use cases (observability, security, networking, etc.) and its ability to run in the kernel context while being orchestrated from user space. Threat actors are increasingly abusing it to create sophisticated backdoors and evade traditional system monitoring tools ...

  • web:www.techprovidence.com

    Synacktiv uncovers LinkPro , a Golang rootkit using eBPF and /etc/ld.so.preload to hide and activate via a "magic packet" .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.