Lightning Framework
- First seen
- 2022-09-01 00:00:00
- Malware type
- rootkit, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:26:57
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
Lightning Framework is a sophisticated, modular malware primarily targeting Linux systems. It is known for its rootkit capabilities, enabling stealthy persistence and control over the infected host. The framework supports multiple functionalities through a plugin-based architecture, making it adaptable for various malicious purposes.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Implant_Lin_Lightning (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Lightning (report)
- intezer.com — Lightning Framework New Linux Threat (report)