LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
-
Updated
Apr 27, 2026 - C
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
awesome-linux-rootkits
🍂Android aarch64 kernel rootkit(driver module)
Utility to find hidden Linux kernel modules
A ring0 Loadable Kernel Module (Linux) for latest kernels 6.x
An example rootkit that gives a userland process root permissions
A rootkit for Android.
A quick LKM rootkit that executes a reverse TCP netcat shell with root privileges.
Ftrace Based Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x up to linux kernel 6.2 on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation - developed by Antonius in 2023 manually
Author of Project Adrishya a rootkit which use ftrace mechanism to hook syscall; (write this because God commanded me); work for both x86_64 and arm; CREDIT-(Oleksii Lozovskyi{ilammy})FOUNDER OF FTRACE HOOKING
64-bit LKM Rootkit builder based on yaml prescription. Working on 5.15.5 kernel
Linux Kernel Rookit Hooking Mechanism
Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x up to linux kernel 6.8 on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
A LKM (Loadable Kernel Module) to execute a command as root; I include a example of using netcat and a compiled(with source and steps on how to compile) reverse shell provided in C.
A ring0 Loadable Kernel Module (Linux) to log all commnds run on the system.
fuxSocy is a linux rootkit made in c and works via system hooking (ftrace)
Examples on Linux Kernel Modules Hacking
Linux LKM rootkit implementing kernel-level stealth techniques including process hiding, file concealment, and network traffic control.
LKM Rootkit targeting Linux v6.x. Security project showcasing syscall hooking, process/file hiding, and privilege escalation via PTE write-protect bypass
Cross-view LKM rootkit detector — proves Elastic Security EDR misses a hidden kernel module, detects it via /proc vs /sys diff
To associate your repository with the lkm-rootkit topic, visit your repo's landing page and select "manage topics."