TripleCross
- First seen
- 2020-05-01 00:00:00
- Malware type
- rootkit
- Last IoC activity
- 2026-07-06 12:29:17
- Profile updated
- 2026-07-07 14:23:06
Targeted industries: technology-and-telecommunications
Context
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
Reports & references
- lolcads.github.io — Bpf Memory Forensics With Volatility3 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Triplecross (report)
- github.com — Triplecross (report)