How Linux Malware Works, From Simple to Sophisticated
Sandfly BlogThis presentation was given by Sandfly Security’s CEO, Craig Rowland, at an invite only 2026-6-17 18:21:33 Author: sandflysecurity.com(查看原文) 阅读量:6 收藏

Sandfly Blog

This presentation was given by Sandfly Security’s CEO, Craig Rowland, at an invite only conference at Ericsson headquarters in Stockholm for telecommunications and mission critical infrastructure providers. 

We cover Linux threats from noisy cryptominers, command and control (C2) frameworks, and network implants like BPFDoor. Plus, we discuss Pluggable Authentication Module (PAM) password stealing backdoors, SSH credential theft, as well as stealth rootkits. You'll learn how these various attacks work and why some are much more difficult to detect. By the end of the video you’ll know what these Linux attack categories are,  why they are a threat, and when attackers may deploy them.

From cloud servers to embedded devices, Sandfly hunts Linux threats agentlessly. We find BPFDoor and stealth rootkits, track SSH keys, and identify the weak passwords that make compromise possible.

Linux Rootkits and Malware from Simple to Sophisticated

Next Steps

Download the PDF here

Contact Ericsson to learn more about agentless Linux security monitoring for critical infrastructure.

To learn more about hunting for Linux stealth rootkits using command line forensics, watch:

Linux Stealth Rootkit Hunting with Command Line Forensics - FIRST 2025 Oslo Cold Incident Response



文章来源: https://sandflysecurity.com/blog/how-linux-malware-works-from-simple-to-sophisticated
如有侵权请联系:admin#unsafe.sh