Oct 172025 LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets Synacktiv uncovered LinkPro, a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.