LinkPro

First seen
2023-05-01 00:00:00
Malware type
rootkit
Family
Malware family
Profile updated
2026-07-07 14:27:02

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Linkpro (report)
  • synacktiv.com — Linkpro Ebpf Rootkit Analysis (report)
  • synacktiv.com — Linkpro Analyse Dun Rootkit Ebpf (report)

External references