eBPF-Based Rootkits
eBPF-based rootkits BPFDoor and Symbiote hide backdoor logic inside the Linux kernel's packet-filtering layer, giving state-linked operators years of undetected access to telecom and financial infrastructure with no open ports or visible processes.