Netskope Threat Labs

Symbiote

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Symbiote is Linux malware that captures credentials and enables backdoor access, implemented as a userland rootkit. It hides its network activity by hooking and hijacking standard file access functions, eBPF, and libpcap functions, which makes it extremely difficult to observe from the compromised host itself.

First seen
October 2022
Last seen
October 2026
Alert Name
Gen:Variant.Trojan.Linux.Symbiote.1
Linux.Trojan.Symbiote
Trojan.Linux.Symbiote.1
Trojan.Linux.Symbiote.2
Trojan.Linux.Symbiote.4