Blogs

Upstart Pumakit Linux rootkit malware examined

[ad_1]

Attacks with Pumakit commence with the deployment of the cron dropper, which executes the ‘/memfd:tgt’ and ‘/memfd:wpn’ payloads, with the former eventually launching the ‘puma.ko’ LKM rootkit module that loads only after ensuring secure boot status and performing kernel symbol scanning.

[ad_2]

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *