Upstart Pumakit Linux rootkit malware examined

Share This Post



Attacks with Pumakit commence with the deployment of the cron dropper, which executes the ‘/memfd:tgt’ and ‘/memfd:wpn’ payloads, with the former eventually launching the ‘puma.ko’ LKM rootkit module that loads only after ensuring secure boot status and performing kernel symbol scanning.



Source link

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Do You Want To Boost Your Business?

drop us a line and keep in touch