LinkPro
An eBPF Rootkit That Hides Both the Attacker and the Backdoor
Executive Summary
LinkPro is a sophisticated Linux rootkit discovered by Synacktiv during an active investigation into a compromised AWS environment.
The initial attack involved an exposed Jenkins server, exploitation of CVE-2024-23897, deployment of a malicious Docker image across multiple Kubernetes clusters, and the subsequent installation of multiple persistent payloads. One of those payloads was LinkPro, a Golang-written rootkit utilizing eBPF for both active process/network concealment and covert network activation.
The Network Illusion
The most significant architectural feature of LinkPro is that it does not merely hide a malicious process running in memory. It natively manipulates the network path itself using XDP.
Initial Attack Chain
The broader intrusion looked approximately like a standard, devastating cloud-native breach:
LinkPro Architecture: Hide & Knock
Synacktiv identified two principal eBPF components inside the rootkit: Hide and Knock.
Attached to kernel tracepoints and kretprobes.
- Hide processes
- Hide network connections
If the rootkit successfully influences what the kernel interfaces return, the defender receives a structurally incomplete picture.
Attached via XDP, TC eBPF, and BPF Maps.
- Hide C2 traffic
- Redirect C2 traffic
Allows LinkPro to remain effectively dormant until it receives a specially crafted "magic" network packet.
The XDP Network Activation
The Knock component is terrifying from a runtime-security perspective. The backdoor does not need to expose an obvious, listening network service that a scanner could find. Instead, it hooks the absolute lowest level of the Linux networking stack (eXpress Data Path - XDP).
Layered Persistence
Synacktiv documented persistence through a systemd service deliberately disguised to resemble the legitimate systemd-resolved service. Furthermore, the malware utilizes fallback concealment mechanisms via /etc/ld.so.preload when its preferred eBPF hiding functionality fails to compile or install on the target kernel.
The Observation Integrity Problem
LinkPro demonstrates that eBPF can be used offensively at practically every single point in the runtime execution lifecycle:
PROCESS OBSERVATION → eBPF HOOKS → NETWORK PROCESSING → XDP/TC → C2 ACTIVATION
The most devastating analytical lesson is structural. The defender is attempting to observe a system where the malicious code is already manipulating the exact observation path the defender relies on.
├── controls network behavior
├── controls visibility
└── controls process representation
↓
User-Space EDR / Tools
Opsonance Point of View
LinkPro is arguably one of the most directly relevant threat architectures for Opsonance. It proves exactly why eBPF-aware security cannot simply assume that all BPF programs are benign observability components. The exact same substrate is now actively used by the attacker.
That creates the core Opsonance design principle: The security layer must fundamentally distinguish between actively observing the runtime, and blindly trusting the runtime's own manipulated representation of itself.
Key Finding
CONCLUSION
LinkPro definitively proves that eBPF is not merely being used to hide malware. It is being weaponized to construct entirely covert network control channels (XDP) functioning silently underneath conventional network visibility. Runtime telemetry trust is now a central element of defensive architecture.