
· haxrob · Linux malware
Hiding in plain sight - Mount namespaces
An exceptionally stealthy technique to hide files and masquerade processes on Linux systems

An exceptionally stealthy technique to hide files and masquerade processes on Linux systems


An exploration into the archeological roots of the BPFDoor Linux malware.

Analysis of a newly discovered Linux based variant of the DPRK attributed FASTCash malware along with background information on payment switches used in financial networks.

A stealthy process stomping method compatible with UNIX-like systems with anti-forensic enhancements for Linux.

Exploring ways malware on Linux and other UNIX-like systems can disguise their process names.