TF-MAL-elf.linkpro
📛 Threat Title
Malware family: LinkPro
Description
ThreatFox malware family `elf.linkpro`. Printable name: LinkPro.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.linkpro
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.linkpro
IOC database
- Type
- domain
- Value
elf.linkpro- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.linkpro
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.linkpro
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberpress.org
A newly uncovered Linux rootkit, dubbed LinkPro , leverages extended Berkeley Packet Filter (eBPF) technology to conceal its presence and maintain persistence on compromised systems. The Synacktiv CSIRT discovered the malware during an investigation of a breached AWS infrastructure.
-
web:cybersecuritynews.com
LinkPro rootkit targets Linux systems using eBPF to hide processes, exploit Jenkins CVE-2024-23897, and backdoor AWS Kubernetes servers.
-
web:cybersixt.com
LinkPro also delivered to Kubernetes nodes a second malware strain and a Golang-based rootkit; it can operate in passive or active mode and only listens for C2 commands after receiving a specific TCP packet, or can initiate contact directly.
-
web:gbhackers.com
Security researchers from Synacktiv CSIRT have uncovered a sophisticated Linux rootkit dubbed LinkPro that leverages eBPF (extended Berkeley Packet Filter).
-
web:malpedia.caad.fkie.fraunhofer.de
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
-
web:rhyno.io
Security researchers have uncovered a highly sophisticated new malware for Linux servers, dubbed LinkPro , that can remain almost completely invisible until activated by a secret signal. This rootkit, discovered during an investigation of a compromised Amazon Web Services (AWS) environment, uses advanced modern Linux features to hide its presence and give attackers a secret backdoor into ...
-
web:thehackernews.com
Synacktiv uncovered LinkPro , a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.synacktiv.com
LinkPro : eBPF rootkit analysis Introduction eBPF (extended Berkeley Packet Filter) is a technology adopted in Linux for its numerous use cases (observability, security, networking, etc.) and its ability to run in the kernel context while being orchestrated from user space. Threat actors are increasingly abusing it to create sophisticated backdoors and evade traditional system monitoring tools ...
-
web:www.techprovidence.com
Synacktiv uncovers LinkPro , a Golang rootkit using eBPF and /etc/ld.so.preload to hide and activate via a "magic packet" .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.