Area
Malware reports
Parent threat
Persistence, Defense Evasion
Finding
https://www.fortinet.com/blog/threat-research/deep-dive-into-a-linux-rootkit-malware
Industry reference
attack:T1547.006:Kernel Modules and Extensions
attack:T1205.002:Socket Filters
Malware reference
wltm
Actor reference
No response
Component
Linux
Scenario
Internal enterprise services