kerberods

Malware type
backdoor, rootkit
Family
Malware family
Profile updated
2026-07-07 14:26:23

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

Kerberods is a Linux-based malware that primarily functions as a backdoor and rootkit, targeting financial, government, and healthcare sectors. It is characterized by its ability to hide its presence and capture user credentials.

Exploited vulnerabilities

  • CVE-2019-3396 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Kerberods (report)
  • anomali.com — Rocke Evolves Its Arsenal With A New Malware Family Written In Golang (report)
  • Trend Micro — Cve 2019 3396 Redux Confluence Vulnerability Exploited To Deliver Cryptocurrency Miner With Rootkit (report)
  • fortinet.com — Rocke Variant Ready To Box Mining Challengers (report)
  • isc.sans.edu — 24916 (report)
  • Cisco Talos — Watchbog Patching (report)

External references