In Puma's footsteps: how to detect a rootkit through its own interface

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Today, our review covers a technically interesting and multifunctional Linux rootkit — Puma, recently researched by colleagues from Elastic Security Labs and Solar 4RAYS.
Puma is a comprehensive kernel-level rootkit (LKM) aimed at long-term stealth persistence in the system and theft of credentials for lateral movement within the victim’s infrastructure. It establishes persistence by replacing the legitimate cron with a modified malicious counterpart consisting of several components:
1️⃣ Loader (
wpn.bin) — responsible for correctly installing the kernel module.2️⃣ Legitimate cron (
tgt.bin) — ensures cron operates properly so the victim doesn’t notice the substitution.3️⃣ LKM module (
audit) — the primary component for intercepting system calls and Linux kernel functions. Thanks to it, the module effectively hides processes, files, directories, and network connections, as well as intercepts sensitive information such as credentials and cryptographic keys.4️⃣ Backdoor (
libs.so) — provides communication with the C2 server, receives commands from attackers, and transmits results.🎯 A Curious Detail
In addition to standard remote control via the C2 server, Puma also uses local control implemented through an overridden rmdir system call: when certain arguments are present, the rootkit interprets the call as a command and returns the execution result to the process that initiated it. The backdoor uses this mechanism to request the remote server configuration from the module or to display intercepted sensitive data.
🔎 What We Managed to Discover
While analyzing Puma, we identified an important vulnerability in the LKM module: it does not verify which process is calling the overridden rmdir to execute commands. Thus, by calling rmdir with certain arguments, one can definitively determine the presence of the rootkit in the system.
📌 Why This Matters
The vulnerability is difficult to remediate: attackers, using the backdoor’s capabilities, can only update its code, but not the code of the kernel module already loaded into the system. That would require significantly more effort. Thus, the vulnerability can be used for rapid detection of Puma in an infrastructure.
🐍 For convenience, we wrote a small Python script that will help you identify the rootkit in a system:
import ctypes
import subprocess
import os
SYS_rmdir = 84
buffer_size = 16
path_buf = ctypes.create_string_buffer(buffer_size)
ctypes.memmove(path_buf, b"zarya.u\0", 7)
libc = ctypes.CDLL("libc.so.6", use_errno=True)
ret = libc.syscall(SYS_rmdir, path_buf)
try:
proc = subprocess.Popen(
"lsmod | grep audit",
shell=True,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
universal_newlines=True
)
output, _ = proc.communicate()
if output.strip():
path_buf2 = ctypes.create_string_buffer(buffer_size)
ctypes.memmove(path_buf2, b"zarya.t.0\0", 9)
ret2 = libc.syscall(SYS_rmdir, path_buf2)
if ret2 == 0:
print(f"Pumakit detected on this machine, module info:\n{output.strip()}")
else:
print("Pumakit wasn't detected at this machine")
else:
print("Pumakit wasn't detected at this machine")
except Exception as e:
print("Error:", e)
Code language: Python (python)Not the most typical case — when a vulnerability works not against the defender, but in their favor. This doesn’t happen often, but it’s precisely what enables accurate detection.
⚠️ If you have detected Puma, then there is almost certainly other malware in the infrastructure as well. Be sure to seek help from information security incident response specialists.
#TI #detect #malware #linux
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



