TripleCross

First seen
2020-05-01 00:00:00
Malware type
rootkit
Last IoC activity
2026-07-06 12:29:17
Profile updated
2026-07-07 14:23:06

Targeted industries: technology-and-telecommunications

Context

According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.

Reports & references

  • lolcads.github.io — Bpf Memory Forensics With Volatility3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Triplecross (report)
  • github.com — Triplecross (report)

External references