Skip to content

Malware

Symbiote

A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit.

A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.


Family metadata imported from Malpedia (Fraunhofer FKIE).