{"id":"829cc24db051e01d0988e88c0ef26a08","title":"eBPF_Rootkit_cpuhide — eBPF_Rootkit_cpuhide · Rootkit · ELF64","md5":"829cc24db051e01d0988e88c0ef26a08","sha256":"1f0457dda40401cbe8409b8375ba9008634771ec5eb9a99c7a84b4e8385d33aa","family":"eBPF_Rootkit_cpuhide","apt":null,"verdict":null,"sample_type":"Rootkit","lang":"C++","file_format":"ELF64","compiler":"GCC","published_at":"2026-08-07T16:00:00.000Z","summary":"该 ELF x86-64 样本为 eBPF 内核级 Rootkit，具备以下核心恶意能力：eBPF 程序注入：使用 BPF map 操作 (bpf_map_update_elem/lookup_elem/delete_elem/get_next_key) 在内核空间执行隐藏逻辑进程隐藏：通过 /tmp/.cpuhide.pids 文件隐藏特定进程 (cpuhide = CPU Hide)，使得 ps/top/ls 等工具无法发现文件描述符隐藏：stat_fd_key 结构体 (tgid + fd) 用于隐藏特定文件描述符，防止网络连接/文件操作被发现PIE 可重定位：启用 ASLR 支持，增加检测难度","url":"https://zseceye.com/report/829cc24db051e01d0988e88c0ef26a08","json_url":"https://zseceye.com/report/829cc24db051e01d0988e88c0ef26a08.json","html_url":"https://zseceye.com/report/829cc24db051e01d0988e88c0ef26a08","hash_urls":{"md5":"https://zseceye.com/hash/829cc24db051e01d0988e88c0ef26a08","sha256":"https://zseceye.com/hash/1f0457dda40401cbe8409b8375ba9008634771ec5eb9a99c7a84b4e8385d33aa"},"search_urls":{"md5":"https://zseceye.com/?q=829cc24db051e01d0988e88c0ef26a08","sha256":"https://zseceye.com/?q=1f0457dda40401cbe8409b8375ba9008634771ec5eb9a99c7a84b4e8385d33aa"},"sample_download_url":"https://zseceye.com/report/829cc24db051e01d0988e88c0ef26a08/sample","sample_filename":"1f0457dda40401cb.zip","iocs":[],"ips":[]}