⤷ Title: Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
Medium
Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
When digital trust becomes the most dangerous vulnerability of the twenty-first century
⤷ Title: Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject “Disco” Password
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
Penetration Testing Tools
Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject "Disco" Password
Trend Micro exposed ZeroDisco, a sophisticated op exploiting Cisco SNMP RCE (CVE-2025-20352) to install Linux rootkits on switches, setting a volatile universal "disco" password and erasing logs.
⤷ Title: Linux Privilege Escalation — Rootkit Scanner
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 08:25:21 GMT
════════════════════════
⌗ Tags: #ejpt #penetration_testing #rootkit_scanner #privilege_escalation #linux_privilege
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 08:25:21 GMT
════════════════════════
⌗ Tags: #ejpt #penetration_testing #rootkit_scanner #privilege_escalation #linux_privilege
Medium
Linux Privilege Escalation — Rootkit Scanner
Linux Privilege
⤷ Title: Binary Architect: ELFSPIRIT Framework Analyzes, Patches, and Camouflages ELF Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 04:23:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Binary Manipulation #cybersecurity #ELF Format #ELFSPIRIT #Malware Research #rootkit #Static Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 04:23:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Binary Manipulation #cybersecurity #ELF Format #ELFSPIRIT #Malware Research #rootkit #Static Analysis
Penetration Testing Tools
Binary Architect: ELFSPIRIT Framework Analyzes, Patches, and Camouflages ELF Files
ELFSPIRIT is a versatile framework for static analysis and injection, allowing users to manipulate, patch, and camouflage every byte within ELF files for research.
⤷ Title: UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
Penetration Testing Tools
UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
The UNC2891 campaign against Indonesian banks used a Raspberry Pi and the CAKETAP rootkit to bypass ATM verification protocols, orchestrating cash-outs via a mule network.
⤷ Title: Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
Penetration Testing Tools
Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
Singularity is an advanced Linux Kernel 6.x rootkit that uses ftrace hooking to provide comprehensive stealth, including process/file hiding and eBPF/EDR detection evasion.
⤷ Title: The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
Penetration Testing Tools
The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
A new commodity has surfaced on underground forums for those seeking to operate more quietly—and for longer. An
⤷ Title: The Kernel Ghost: Mustang Panda’s New Rootkit Blinds Antivirus to Deploy ToneShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:24:21 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #HoneyMyte #kaspersky #Malware 2025 #Microsoft Defender #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Thailand #Toneshell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:24:21 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #HoneyMyte #kaspersky #Malware 2025 #Microsoft Defender #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Thailand #Toneshell
Information Security News
The Kernel Ghost: Mustang Panda’s New Rootkit Blinds Antivirus to Deploy ToneShell
Cyber-espionage attributed to the Chinese group HoneyMyte—also known as Mustang Panda and Bronze President—has reached a new level. Researchers have observed the deployment of an advanced version …
⤷ Title: The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
Daily CyberSecurity
The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
The notorious cyber-espionage group HoneyMyte (also known as Mustang Panda or Bronze President) has dramatically upgraded its arsenal, deploying a sophisticated kernel-mode rootkit to entrench its…
⤷ Title: Digital Siege: How Singapore Thwarted UNC3886’s Surgical Strike on its Telecom Backbone
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 07:51:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #CSA #Cyber Espionage #IMDA #M1 #Operation Cyber Guardian #rootkit #Simba #Singapore #Singtel #StarHub #Tech News 2026 #UNC3886 #zero_day exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 07:51:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #CSA #Cyber Espionage #IMDA #M1 #Operation Cyber Guardian #rootkit #Simba #Singapore #Singtel #StarHub #Tech News 2026 #UNC3886 #zero_day exploit
Penetration Testing Tools
Digital Siege: How Singapore Thwarted UNC3886’s Surgical Strike on its Telecom Backbone
Singapore’s preeminent telecommunications providers have fallen prey to a sophisticated cyber espionage campaign orchestrated by the formidable adversarial
⤷ Title: Nidhogg: multi-functional rootkit for red teams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Nidhogg #red teams #rootkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Nidhogg #red teams #rootkit
Penetration Testing Tools
Nidhogg: multi-functional rootkit for red teams
Nidhogg is a multi-functional rootkit for red teams. The goal of Nidhogg is to provide an all-in-one and easy-to-use rootkit
⤷ Title: The Katana Siege: How 30,000 Android TV Boxes Were Hijacked into a 150Gbps DDoS Army
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 06:36:40 +0000
════════════════════════
⌗ Tags: #Malware #ADB Exploit #Android TV #Cyber Security 2026 #DDOS attack #IoT Security #Katana Botnet #malware analysis #Mirai malware #Nokia Deepfield #rootkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 06:36:40 +0000
════════════════════════
⌗ Tags: #Malware #ADB Exploit #Android TV #Cyber Security 2026 #DDOS attack #IoT Security #Katana Botnet #malware analysis #Mirai malware #Nokia Deepfield #rootkit
Penetration Testing Tools
The Katana Siege: How 30,000 Android TV Boxes Were Hijacked into a 150Gbps DDoS Army
The Katana botnet has usurped no fewer than thirty thousand Android-based television set-top boxes, transfiguring these economical apparatuses
⤷ Title: The Kernel’s Ghost Hunter: Unmasking Stealth Rootkits with klint
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 08:52:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BPF Security #Cybersecurity 2026 #Infosec Tools #Kernel Integrity #klint #Linux Kernel #malware analysis #open source #Rootkit Detection #Syscall Hijacking #Threat Hunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 08:52:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BPF Security #Cybersecurity 2026 #Infosec Tools #Kernel Integrity #klint #Linux Kernel #malware analysis #open source #Rootkit Detection #Syscall Hijacking #Threat Hunting
Penetration Testing Tools
The Kernel’s Ghost Hunter: Unmasking Stealth Rootkits with klint
Detect stealth rootkits with klint. This Linux kernel integrity scanner cross-references MSRs, IDT, and syscall tables to find hidden threats in 2026.
⤷ Title: Argus: Building a Linux Kernel Rootkit Detection Module
════════════════════════
𐀪 Author: Ananthanr Off
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 12:33:43 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #rootkit #systems_programming #linux_kernel
════════════════════════
𐀪 Author: Ananthanr Off
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 12:33:43 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #rootkit #systems_programming #linux_kernel
Medium
Argus: Building a Linux Kernel Rootkit Detection Module
Argus is a Linux kernel rootkit detector using cross-view analysis to uncover hidden system activity.
⤷ Title: Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
Penetration Testing Tools
Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
The novel Linux implant, Quasar Linux, poses a formidable threat not merely to individual workstations but to the
⤷ Title: PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:09:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Credential Harvesting #Cybercrime #Flare #infosec #Linux Security #Malware Analysis #PAM Stack #PamDOORa #rootkit #ssh backdoor #SysAdmin
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:09:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Credential Harvesting #Cybercrime #Flare #infosec #Linux Security #Malware Analysis #PAM Stack #PamDOORa #rootkit #ssh backdoor #SysAdmin
Daily CyberSecurity
PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs
Flare unmasks PamDOORa: a $1,600 Linux backdoor that hijacks the PAM stack to harvest credentials and manipulate authentication logs to evade detection.
⤷ Title: HoneyMyte’s CoolClient Backdoor Adds Signed Kernel Rootkit Driver
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 12:06:52 +0000
════════════════════════
⌗ Tags: #Malware #CoolClient #DLL Sideloading #HoneyMyte #Kernel Driver #Mustang Panda #PlugX #rootkit
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 12:06:52 +0000
════════════════════════
⌗ Tags: #Malware #CoolClient #DLL Sideloading #HoneyMyte #Kernel Driver #Mustang Panda #PlugX #rootkit
Information Security News
HoneyMyte’s CoolClient Backdoor Adds Signed Kernel Rootkit Driver
The threat group HoneyMyte, also tracked as Mustang Panda, has begun deploying an updated version of its CoolClient backdoor alongside a signed Windows kernel-level driver. Kaspersky’s Secur…