The Containment Era is here. →Explore

Executive Summary

In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations.

This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.

Why This Matters Now

LinkPro demonstrates how attackers exploit advanced Linux kernel features like eBPF to create highly evasive rootkits, making existing security controls obsolete in some cloud environments. With the adoption of cloud-native and hybrid infrastructures accelerating, organizations must urgently update detection and response strategies against modern, kernel-level threats before similar tactics proliferate.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

LinkPro leveraged eBPF kernel modules to conceal processes and network activity, making it nearly invisible to conventional monitoring and anti-malware tools.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west traffic controls, inline threat detection, and strict egress policies would have significantly limited the attacker's ability to compromise, persist, move laterally, and exfiltrate data. Real-time workload-level controls, anomaly detection, and unified visibility would have enabled earlier detection and containment of the eBPF rootkit.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Inbound exploitation attempts are prevented at the network perimeter.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Suspicious privilege escalation or kernel module loading generates alerts.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Lateral movement between workloads is blocked or promptly detected.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Malicious command and control channels are detected and disrupted.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unapproved outbound exfiltration channels are blocked or logged.

Impact (Mitigations)

Ongoing malicious persistence is rapidly detected and responded to.

Impact at a Glance

Affected Business Functions

  • Continuous Integration/Continuous Deployment (CI/CD) pipelines
  • Software development operations
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of source code repositories and sensitive build artifacts due to unauthorized access to the Jenkins server.

Recommended Actions

  • Enforce cloud firewall and microsegmentation policies to reduce external and internal attack surfaces.
  • Deploy inline threat detection and anomaly response to catch abnormal privilege escalation and kernel manipulations in real time.
  • Restrict and monitor east-west traffic with zero trust segmentation and centralized visibility across all cloud workloads.
  • Implement strict egress filtering to block or log unauthorized outbound connections and detect covert exfiltration attempts.
  • Continuously baseline normal network and system behavior to enable faster detection of stealthy rootkit techniques leveraging eBPF or other advanced persistence methods.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image