⤷ Title: Koske Malware: AI-Generated Cryptojacker Hides in Panda Images, Targets Linux Servers with Rootkit Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 01:00:02 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cryptojacking #cybersecurity #JupyterLab #Koske Malware #Linux #Polyglot Files #rootkit #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 01:00:02 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cryptojacking #cybersecurity #JupyterLab #Koske Malware #Linux #Polyglot Files #rootkit #threat intelligence
Penetration Testing Tools
Koske Malware: AI-Generated Cryptojacker Hides in Panda Images, Targets Linux Servers with Rootkit Stealth
AquaSec uncovers Koske, a new cryptojacking malware potentially AI-generated, hiding in innocent-looking images to silently infect Linux servers and evade detection with rootkit stealth.
⤷ Title: ️ Kernel Module Security and Intrusion Detection on Linux
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 09:47:01 GMT
════════════════════════
⌗ Tags: #security #rootkit_detection #linux_security #cybersecurity #technology
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 09:47:01 GMT
════════════════════════
⌗ Tags: #security #rootkit_detection #linux_security #cybersecurity #technology
Medium
🛡️ Kernel Module Security and Intrusion Detection on Linux
The Linux operating system, with its modular architecture, allows dynamic modules to be loaded into the kernel for flexibility. These…
⤷ Title: “A True Nightmare”: Leaked Archive Reveals a Highly Sophisticated Linux Rootkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 04:20:15 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Espionage #Kimsuky #Linux #North Korea #Phrack #rootkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 Aug 2025 04:20:15 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #Espionage #Kimsuky #Linux #North Korea #Phrack #rootkit
Penetration Testing Tools
"A True Nightmare": Leaked Archive Reveals a Highly Sophisticated Linux Rootkit
A new issue of the hacker magazine Phrack contains a leaked archive detailing a sophisticated Linux rootkit with advanced stealth capabilities used by hackers.
⤷ Title: Building a basic x64 Linux Rootkit
════════════════════════
𐀪 Author: Keiran Smith
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 13:39:33 GMT
════════════════════════
⌗ Tags: #rootkit #syscalls #linux #hacking #pentesting
════════════════════════
𐀪 Author: Keiran Smith
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 13:39:33 GMT
════════════════════════
⌗ Tags: #rootkit #syscalls #linux #hacking #pentesting
Medium
Building a basic x64 Linux Rootkit
A Linux rootkit is a kernel module that alters the behaviour of the kernel to hide activity and provide covert functionality. In this…
⤷ Title: Critical Flaws in Supermicro BMC Enable Irreversible AI Server Rootkits Below the OS Level
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:59:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Binarly #BMC #CVE_2025_7937 #data center #firmware #rootkit #Supermicro #Supply Chain #UEFI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:59:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Binarly #BMC #CVE_2025_7937 #data center #firmware #rootkit #Supermicro #Supply Chain #UEFI
Penetration Testing Tools
Critical Flaws in Supermicro BMC Enable Irreversible AI Server Rootkits Below the OS Level
Critical Supermicro BMC flaws (CVE-2025-7937/6198) enable malicious, irreversible firmware to be installed, compromising servers at the root-of-trust level.
⤷ Title: Linux Rootkits: A Comprehensive Security Guide
════════════════════════
𐀪 Author: ThamizhElango Natarajan
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 02:19:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware_analysis #infosec #rootkit #linux_security
════════════════════════
𐀪 Author: ThamizhElango Natarajan
════════════════════════
ⴵ Time: Sat, 04 Oct 2025 02:19:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware_analysis #infosec #rootkit #linux_security
Medium
Linux Rootkits: A Comprehensive Security Guide
Introduction
⤷ Title: FlipSwitch Rootkit Bypasses Linux Kernel 6.9 Defenses with Surgical Bytecode Hooking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:51:10 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Defense Evasion #Elastic #FlipSwitch #Kernel 6.9 #Linux Kernel #rootkit #Syscall Hooking #x86_64
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:51:10 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Defense Evasion #Elastic #FlipSwitch #Kernel 6.9 #Linux Kernel #rootkit #Syscall Hooking #x86_64
Penetration Testing Tools
FlipSwitch Rootkit Bypasses Linux Kernel 6.9 Defenses with Surgical Bytecode Hooking
The FlipSwitch rootkit uses bytecode modification to intercept syscalls in Linux kernel 6.9, bypassing the new switch-based dispatcher that rendered traditional sys_call_table hooking useless.
⤷ Title: Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
Medium
Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
When digital trust becomes the most dangerous vulnerability of the twenty-first century
⤷ Title: Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject “Disco” Password
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
Penetration Testing Tools
Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject "Disco" Password
Trend Micro exposed ZeroDisco, a sophisticated op exploiting Cisco SNMP RCE (CVE-2025-20352) to install Linux rootkits on switches, setting a volatile universal "disco" password and erasing logs.
⤷ Title: Linux Privilege Escalation — Rootkit Scanner
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 08:25:21 GMT
════════════════════════
⌗ Tags: #ejpt #penetration_testing #rootkit_scanner #privilege_escalation #linux_privilege
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 19 Oct 2025 08:25:21 GMT
════════════════════════
⌗ Tags: #ejpt #penetration_testing #rootkit_scanner #privilege_escalation #linux_privilege
Medium
Linux Privilege Escalation — Rootkit Scanner
Linux Privilege
⤷ Title: Binary Architect: ELFSPIRIT Framework Analyzes, Patches, and Camouflages ELF Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 04:23:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Binary Manipulation #cybersecurity #ELF Format #ELFSPIRIT #Malware Research #rootkit #Static Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 04:23:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Binary Manipulation #cybersecurity #ELF Format #ELFSPIRIT #Malware Research #rootkit #Static Analysis
Penetration Testing Tools
Binary Architect: ELFSPIRIT Framework Analyzes, Patches, and Camouflages ELF Files
ELFSPIRIT is a versatile framework for static analysis and injection, allowing users to manipulate, patch, and camouflage every byte within ELF files for research.
⤷ Title: UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
Penetration Testing Tools
UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
The UNC2891 campaign against Indonesian banks used a Raspberry Pi and the CAKETAP rootkit to bypass ATM verification protocols, orchestrating cash-outs via a mule network.
⤷ Title: Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
Penetration Testing Tools
Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
Singularity is an advanced Linux Kernel 6.x rootkit that uses ftrace hooking to provide comprehensive stealth, including process/file hiding and eBPF/EDR detection evasion.
⤷ Title: The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:23:58 +0000
════════════════════════
⌗ Tags: #Malware #AlphaGhoul #Early Boot Persistence #EDR Bypass #endpoint security #HVCI #KrakenLabs #Malware 2025 #Microsoft Defender #NtKiller #rootkit #UAC bypass
Penetration Testing Tools
The Silence of the Scans: New NtKiller Utility Disables Antivirus at the Root
A new commodity has surfaced on underground forums for those seeking to operate more quietly—and for longer. An
⤷ Title: The Kernel Ghost: Mustang Panda’s New Rootkit Blinds Antivirus to Deploy ToneShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:24:21 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #HoneyMyte #kaspersky #Malware 2025 #Microsoft Defender #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Thailand #Toneshell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:24:21 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #HoneyMyte #kaspersky #Malware 2025 #Microsoft Defender #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Thailand #Toneshell
Information Security News
The Kernel Ghost: Mustang Panda’s New Rootkit Blinds Antivirus to Deploy ToneShell
Cyber-espionage attributed to the Chinese group HoneyMyte—also known as Mustang Panda and Bronze President—has reached a new level. Researchers have observed the deployment of an advanced version …
⤷ Title: The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT group #cyber_espionage #HoneyMyte #kaspersky #Kernel_Mode #Microsoft Defender Bypass #Mustang Panda #Myanmar #ProjectConfiguration.sys #rootkit #Southeast Asia #Thailand #ToneShell
Daily CyberSecurity
The Ghost in the Kernel: How HoneyMyte Weaponized a Rootkit to Hijack Asian Governments
The notorious cyber-espionage group HoneyMyte (also known as Mustang Panda or Bronze President) has dramatically upgraded its arsenal, deploying a sophisticated kernel-mode rootkit to entrench its…