LinkPro
- First seen
- 2023-05-01 00:00:00
- Malware type
- rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 14:27:02
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Linkpro (report)
- synacktiv.com — Linkpro Ebpf Rootkit Analysis (report)
- synacktiv.com — Linkpro Analyse Dun Rootkit Ebpf (report)