Reverse engineering Linux malware
2025-12-05 17:50:42.104725+01 by Dan Lyke 0 comments
LinkPro: eBPF rootkit analysis
LinkPro targets GNU/Linux systems and is developed in Golang. The Synacktiv CSIRT names it LinkPro in reference to the symbol defining its main module:
github.com/link-pro/link-client. The GitHub account link-pro has no public repositories or contributions. LinkPro uses eBPF technology to only activate upon receiving a "magic packet", and to conceal itself on the compromised system.
(eBPF is the "extended Berkeley Packet Filter")