Aquaboutic | Focus Security Research | Vulnerability Exploit | POC

Home

rootkit: linux rootkit

Posted by fleschner at 2020-04-16
all

Yet another LKM rootkit for Linux. It hooks syscall table. Features: Hide files that ends on configured suffix (FILE_SUFFIX - ".rootkit" by default).

FILE_SUFFIX COMMAND_CONTAINS

Examples:

.//./malicious_process wget http://old-releases.ubuntu.com/releases/zesty/ubuntu-17.04-desktop-amd64.iso .//./ /etc/http_requests[FILE_SUFFIX] /etc/passwords[FILE_SUFFIX] lsmod /proc/modules /sys/module/ rmmod UNABLE_TO_UNLOAD rootkit.c Linux x 4.13.0-kali1-amd64 #1 SMP Debian 4.13.10-1kali2 (2017-11-08) x86_64 GNU/Linux