[ << ALL_FEED ]

In Puma's footsteps: how to detect a rootkit through its own interface

More in General

🐾 Following in Puma’s Footsteps: How to Detect a Rootkit Through Its Own Interface

Today, our review covers a technically interesting and multifunctional Linux rootkit — Puma, recently researched by colleagues from Elastic Security Labs and Solar 4RAYS.

Puma is a comprehensive kernel-level rootkit (LKM) aimed at long-term stealth persistence in the system and theft of credentials for lateral movement within the victim’s infrastructure. It establishes persistence by replacing the legitimate cron with a modified malicious counterpart consisting of several components:

1️⃣ Loader (wpn.bin) — responsible for correctly installing the kernel module.

2️⃣ Legitimate cron (tgt.bin) — ensures cron operates properly so the victim doesn’t notice the substitution.

3️⃣ LKM module (audit) — the primary component for intercepting system calls and Linux kernel functions. Thanks to it, the module effectively hides processes, files, directories, and network connections, as well as intercepts sensitive information such as credentials and cryptographic keys.

4️⃣ Backdoor (libs.so) — provides communication with the C2 server, receives commands from attackers, and transmits results.

🎯 A Curious Detail

In addition to standard remote control via the C2 server, Puma also uses local control implemented through an overridden rmdir system call: when certain arguments are present, the rootkit interprets the call as a command and returns the execution result to the process that initiated it. The backdoor uses this mechanism to request the remote server configuration from the module or to display intercepted sensitive data.

🔎 What We Managed to Discover

While analyzing Puma, we identified an important vulnerability in the LKM module: it does not verify which process is calling the overridden rmdir to execute commands. Thus, by calling rmdir with certain arguments, one can definitively determine the presence of the rootkit in the system.

📌 Why This Matters

The vulnerability is difficult to remediate: attackers, using the backdoor’s capabilities, can only update its code, but not the code of the kernel module already loaded into the system. That would require significantly more effort. Thus, the vulnerability can be used for rapid detection of Puma in an infrastructure.

🐍 For convenience, we wrote a small Python script that will help you identify the rootkit in a system:

import ctypes
import subprocess
import os

SYS_rmdir = 84  

buffer_size = 16
path_buf = ctypes.create_string_buffer(buffer_size)
ctypes.memmove(path_buf, b"zarya.u\0", 7)

libc = ctypes.CDLL("libc.so.6", use_errno=True)
ret = libc.syscall(SYS_rmdir, path_buf)

try:
    proc = subprocess.Popen(
        "lsmod | grep audit",
        shell=True,
        stdout=subprocess.PIPE,
        stderr=subprocess.PIPE,
        universal_newlines=True
)
    output, _ = proc.communicate()

    if output.strip():
        path_buf2 = ctypes.create_string_buffer(buffer_size)
        ctypes.memmove(path_buf2, b"zarya.t.0\0", 9)
        ret2 = libc.syscall(SYS_rmdir, path_buf2)
        
        if ret2 == 0:
            print(f"Pumakit detected on this machine, module info:\n{output.strip()}")
        else:
            print("Pumakit wasn't detected at this machine")
    else:
        print("Pumakit wasn't detected at this machine")

except Exception as e:
    print("Error:", e)
Code language: Python (python)


Not the most typical case — when a vulnerability works not against the defender, but in their favor. This doesn’t happen often, but it’s precisely what enables accurate detection.

⚠️ If you have detected Puma, then there is almost certainly other malware in the infrastructure as well. Be sure to seek help from information security incident response specialists.

#TI #detect #malware #linux
@ptescalator

More from ti_author

More from ti_author

More in General