EBPF — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
December 3, 2025
Last Seen
June 11, 2026

eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that lets users run sandboxed programs inside the kernel for tasks such as networking, tracing, and security.

Overview

eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that lets users run sandboxed programs inside the kernel for tasks such as networking, tracing, and security. It provides deep visibility and kernel-space control, which attackers can abuse to hide activity or maintain persistence. Recent findings show BPFDoor and Symbiote rootkits leveraging eBPF filters to compromise Linux systems, underscoring a kernel-level attack surface in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • Atomic Arch npm Campaign Adds Malicious Dependency — Sonatype · June 11, 2026
  • Cloudflare Debuts C-Based Custom DDoS Shields for Magic Transit — Notebookcheck · April 1, 2026
  • VoidLink Rootkit Uses eBPF and Kernel Modules to Hide Deep Inside Linux Systems — Cybersecuritynews · March 26, 2026
  • Linux Rootkits Using Advanced eBPF and io_uring Techniques — Cybersecuritynews · March 6, 2026
  • LKM Rootkit Singularity vs eBPF security tools — Reddit · January 21, 2026
  • BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters — Cybersecuritynews · December 3, 2025

CVSS v3.1 Breakdown