Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters

## Cybersecurity: Linux Rootkits Exploiting eBPF Technology

Cybersecurity: Linux Rootkits Exploiting eBPF Technology

Two advanced Linux rootkits, BPFDoor and Symbiote, present significant threats to network security by utilizing eBPF technology to conceal their activities from conventional detection systems.

Originating in 2021, these rootkits exemplify a sophisticated class of malware that grants kernel-level access and demonstrates advanced evasion capabilities.

In 2025, security researchers identified 151 new instances of BPFDoor and three instances of Symbiote, indicating ongoing development and deployment against critical infrastructure.

These rootkits exploit eBPF (extended Berkeley Packet Filter), a Linux kernel technology introduced in 2015 for loading sandboxed programs into the kernel to inspect and modify network packets and system calls.

While eBPF is intended for legitimate network monitoring and security purposes, it has been misused to create hard-to-detect backdoors capable of intercepting communications and maintaining stealthy access bypassing traditional security alerts.

These threats signify a strategic shift in malware development. Unlike widespread ransomware or botnets, eBPF-based rootkits require specialized expertise for development and deployment.

This exclusivity makes them a preferred choice for state-sponsored attackers aiming for reliable, long-term access to critical systems.

Unlike widespread ransomware or botnets, eBPF-based rootkits require specialized expertise for development and deployment.
Harper Fairbanks · Thehackingpost

Fortinet security analysts identified that both malware families continue to evolve, incorporating sophisticated filtering mechanisms to bypass modern security defenses.

Recent variants show tactical advancements. The latest version of Symbiote, as of July 2025, supports IPv4 and IPv6 packets across TCP, UDP, and SCTP protocols on non-standard ports, including 54778, 58870, 59666, 54879, 57987, 64322, 45677, and 63227.

This expanded port range enables the malware to conduct command and control communications through port hopping, complicating efforts by network administrators to block malicious traffic without causing false positives.

The rootkits have improved their ability to hide command and control communications. BPFDoor's 2025 variants support IPv6 traffic and filter DNS traffic on port 53 over both IPv4 and IPv6 protocols.

By disguising as legitimate DNS queries, the malware blends into typical network activity that security teams usually consider harmless.

Advertisement

The technical implementation involves eBPF bytecode that attaches directly to network sockets, acting as a kernel-level packet filter that is invisible to userspace tools.

Upon analysis with reverse engineering tools like Radare2, the bytecode reveals inspection routines that identify command packets, then silently pass them to command servers while discarding other traffic.

Detection is challenging because eBPF filters operate at the kernel level, beyond the reach of standard security monitoring tools .

Fortinet's protection mechanisms now identify these threats using signature-based antivirus engines and specialized IPS signatures that monitor reverse shell communications and botnet activity.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories