Suspicious Kernel Module Load Or Unload For Rootkit Deployment via PUMAKIT

PremiumReviewedSigma · Low · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-18
Updated
2026-09-18

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects invocation of module management utilities that insert or remove Linux kernel modules which the PUMAKIT rootkit relies on to load its kernel component and manipulate the running kernel. Adversaries load a malicious LKM to gain kernel level control and conceal processes files and network activity.

Related detections9 linkedT1014 — drag to rearrange
Malicious VoidLink Kernel Module Load via Insmod (via process_creation)
Suspicious Fileless Execution From Memory File Descriptor via PUMAKIT
Malicious ABYSSWORKER EDR-Killer Driver Load via smuol.sys
Possible AF_ALG Privilege Escalation via algif_aead Module Load
Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
Malicious Koske Userland Rootkit Installation via ld.so.preload (via file_event)
Malicious TeamTNT prochider Rootkit Deployment as Shared Object (via file_event)
Malicious perfctl Rootkit Library Drop via ld.so.preload (via file_event)
Suspicious Kernel Extension Load on macOS (via process_creation)
Suspicious Kernel Module Load Or Unload For Rootkit Deployment via PUMAKIT
Pivot detection · T1014 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.