h3xduck / TripleCross

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
GNU General Public License v3.0
1.79k stars 221 forks source link

Use TC program to filter egress traffic and camouflage c&c traffic #22

Closed h3xduck closed 2 years ago