LinkPro

An eBPF Rootkit That Hides Both the Attacker and the Backdoor

INCIDENT TYPE
Kubernetes compromise, Linux rootkit, eBPF network concealment
PRIMARY RESEARCH
Synacktiv CSIRT
ASSESSMENT
Critical relevance to runtime-security architecture

Executive Summary

LinkPro is a sophisticated Linux rootkit discovered by Synacktiv during an active investigation into a compromised AWS environment.

The initial attack involved an exposed Jenkins server, exploitation of CVE-2024-23897, deployment of a malicious Docker image across multiple Kubernetes clusters, and the subsequent installation of multiple persistent payloads. One of those payloads was LinkPro, a Golang-written rootkit utilizing eBPF for both active process/network concealment and covert network activation.

The Network Illusion

The most significant architectural feature of LinkPro is that it does not merely hide a malicious process running in memory. It natively manipulates the network path itself using XDP.

Initial Attack Chain

The broader intrusion looked approximately like a standard, devastating cloud-native breach:

Exposed Jenkins
↓
CVE-2024-23897 (Code Execution)
↓
Malicious Docker Image
↓
Kubernetes Clusters
↓
vShell / vGet / LinkPro Installed
↓
KERNEL-LEVEL STEALTH

LinkPro Architecture: Hide & Knock

Synacktiv identified two principal eBPF components inside the rootkit: Hide and Knock.

THE "HIDE" MODULE

Attached to kernel tracepoints and kretprobes.

  • Hide processes
  • Hide network connections

If the rootkit successfully influences what the kernel interfaces return, the defender receives a structurally incomplete picture.

THE "KNOCK" MODULE

Attached via XDP, TC eBPF, and BPF Maps.

  • Hide C2 traffic
  • Redirect C2 traffic

Allows LinkPro to remain effectively dormant until it receives a specially crafted "magic" network packet.

The XDP Network Activation

The Knock component is terrifying from a runtime-security perspective. The backdoor does not need to expose an obvious, listening network service that a scanner could find. Instead, it hooks the absolute lowest level of the Linux networking stack (eXpress Data Path - XDP).

THE COVERT NETWORK CHANNEL
INTERNET
↓
Network Packet Arrival
↓
XDP Hook (eBPF)
Normal Packet
↓
Ignore (Pass to OS)
Magic Packet
↓
ACTIVATE C2

Layered Persistence

Synacktiv documented persistence through a systemd service deliberately disguised to resemble the legitimate systemd-resolved service. Furthermore, the malware utilizes fallback concealment mechanisms via /etc/ld.so.preload when its preferred eBPF hiding functionality fails to compile or install on the target kernel.

LINKPRO FRAMEWORK
├── eBPF ├── systemd └── LD_PRELOAD
↓
SURVIVE / HIDE

The Observation Integrity Problem

LinkPro demonstrates that eBPF can be used offensively at practically every single point in the runtime execution lifecycle:

PROCESS OBSERVATION → eBPF HOOKS → NETWORK PROCESSING → XDP/TC → C2 ACTIVATION

The most devastating analytical lesson is structural. The defender is attempting to observe a system where the malicious code is already manipulating the exact observation path the defender relies on.

THE TELEMETRY INTEGRITY PARADOX
Attacker Kernel
├── controls network behavior
├── controls visibility
└── controls process representation
↓
User-Space EDR / Tools

Opsonance Point of View

LinkPro is arguably one of the most directly relevant threat architectures for Opsonance. It proves exactly why eBPF-aware security cannot simply assume that all BPF programs are benign observability components. The exact same substrate is now actively used by the attacker.

1. What is executing?
2. What kernel hooks exist?
3. What BPF programs exist?
4. What network paths are being modified?
5. What process state is being concealed?
6. What runtime behavior produced those changes?

That creates the core Opsonance design principle: The security layer must fundamentally distinguish between actively observing the runtime, and blindly trusting the runtime's own manipulated representation of itself.

Key Finding

CONCLUSION

LinkPro definitively proves that eBPF is not merely being used to hide malware. It is being weaponized to construct entirely covert network control channels (XDP) functioning silently underneath conventional network visibility. Runtime telemetry trust is now a central element of defensive architecture.

References