Symbiote
- Malware type
- backdoor, credential-stealer, rootkit
- Last IoC activity
- 2026-07-18 13:01:16
- Profile updated
- 2026-07-07 14:22:53
Context
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.
Reports & references
- Trend Micro — Detecting Bpfdoor Backdoor Variants Abusing Bpf Filters (report)
- intezer.com — Orbit New Undetected Linux Threat (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Symbiote (report)
- cybergeeks.tech — How To Analyze Linux Malware A Case Study Of Symbiote (report)
- blogs.blackberry.com — Symbiote A New Nearly Impossible To Detect Linux Threat (report)