Solved Looking for confirmation or dismiss. Presumed rootkit on Windows, went Linux and IOS.

Solved issue
Feed that to your LLM. Stop living in a goldfish bowl. Count how many hypervisors are baked into that kernel.
 

Attachments

  • Screenshot_20260507_221633_File Viewer.jpg
    Screenshot_20260507_221633_File Viewer.jpg
    452.7 KB · Views: 60
  • Screenshot_20260507_222050_File Viewer.jpg
    Screenshot_20260507_222050_File Viewer.jpg
    471.6 KB · Views: 54
  • Screenshot_20260507_222038_File Viewer.jpg
    Screenshot_20260507_222038_File Viewer.jpg
    447.6 KB · Views: 55
  • Screenshot_20260507_222026_File Viewer.jpg
    Screenshot_20260507_222026_File Viewer.jpg
    460 KB · Views: 44
  • Screenshot_20260507_222016_File Viewer.jpg
    Screenshot_20260507_222016_File Viewer.jpg
    487.5 KB · Views: 69
  • Screenshot_20260507_222002_File Viewer.jpg
    Screenshot_20260507_222002_File Viewer.jpg
    435.3 KB · Views: 68
  • Screenshot_20260507_221949_File Viewer.jpg
    Screenshot_20260507_221949_File Viewer.jpg
    466.7 KB · Views: 41
  • Screenshot_20260507_221937_File Viewer.jpg
    Screenshot_20260507_221937_File Viewer.jpg
    441.4 KB · Views: 65
  • Screenshot_20260507_221925_File Viewer.jpg
    Screenshot_20260507_221925_File Viewer.jpg
    487.7 KB · Views: 49
  • Screenshot_20260507_221817_File Viewer.jpg
    Screenshot_20260507_221817_File Viewer.jpg
    472.7 KB · Views: 53
  • Screenshot_20260507_221803_File Viewer.jpg
    Screenshot_20260507_221803_File Viewer.jpg
    477.2 KB · Views: 65
  • Screenshot_20260507_221643_File Viewer.jpg
    Screenshot_20260507_221643_File Viewer.jpg
    455.7 KB · Views: 38
  • Screenshot_20260507_221655_File Viewer.jpg
    Screenshot_20260507_221655_File Viewer.jpg
    451.8 KB · Views: 70
  • Screenshot_20260507_221705_File Viewer.jpg
    Screenshot_20260507_221705_File Viewer.jpg
    439.9 KB · Views: 74
  • Screenshot_20260507_221714_File Viewer.jpg
    Screenshot_20260507_221714_File Viewer.jpg
    482.9 KB · Views: 71
  • Screenshot_20260507_221727_File Viewer.jpg
    Screenshot_20260507_221727_File Viewer.jpg
    466.7 KB · Views: 62
  • Screenshot_20260507_221739_File Viewer.jpg
    Screenshot_20260507_221739_File Viewer.jpg
    444.3 KB · Views: 39
  • Screenshot_20260507_221750_File Viewer.jpg
    Screenshot_20260507_221750_File Viewer.jpg
    433.9 KB · Views: 61


hard to read this wall of text and pictures. So I feed text from this page to LLM.


Here's the TL;DR summary:


What CoincidentalHell (OP) claims:
Starting February 2026, they believe they found a sophisticated, nation-state-level rootkit across Windows, Linux (Ubuntu on an HP EliteDesk and ASUS machine), and iOS. They describe a 9-tier persistence model including: firmware/UEFI compromise, a custom MOK certificate enrolled since 2019, a hidden Xen hypervisor running below the OS, NVMe firmware implants surviving disk wipes, SMM (Ring -2) persistence, a trojanized Ubuntu ISO, keyboard USB injection, and active counterintelligence blocking forensic tools in real time.


How the reports were made: Largely AI-generated — the user admits "I mostly get AI to write it and I'll fact check points." They used Claude, Google Gemini, and GitHub Copilot to analyze logs and write the reports. This is a critical detail.


Community reaction: Mostly dismissive. One member (Trml) asked polite clarifying questions. Veteran members Condobloke and bob466 were openly skeptical, joking about trolls. CaffeineAddict explicitly called out DarthVader's follow-up post, pointing out that kernel config flags are not evidence of being hacked.


My honest read on this: This almost certainly isn't a real sophisticated rootkit. The pattern is a well-known phenomenon: a worried user feeds system logs to an AI and asks "is this suspicious?" — the AI, trying to be helpful, flags ambiguous things as potentially suspicious — the user feeds those AI responses back into new AI sessions as "evidence" — the AI builds an increasingly elaborate theory on top of prior AI output. This creates a self-reinforcing cycle. Many of the specific "findings" (Intel UCSI tables, certain kernel configs, SSDT count, AppArmor profiles) have completely mundane explanations. The "BORT" ACPI table they're alarmed about is probably OCR misreading "BOOT."


The reports are genuinely well-structured and use real technical terminology correctly, which is why they look convincing — but that's a property of the AI that wrote them, not evidence of a real attack.
The AI only wrote up what I found, most of it was counter fact checked from other sources. Those reports had nothing on the actual, we were convinced it was vtoy and ventoy avenue but no, I found it, all, beat it. Then it came back lol. Whilst I fully understand what you are saying, I used AI as a tool, always ran live sessions with no context agents elsewhere and then pieced it together later what report was this - not been online for awhile. —after checking this was bloody ages ago!

I won’t post here, up to report 51 - tldr hypervisor rooty have watched it live inject and alter ISOs, caught it rebuilding images, had it offline 8 days I believe when I broke it. At the end of the day what I always say, AI or not, noob or not, it doesn’t change the fact that the computer gets hyjacked, offline or online, every install, every boot. I would have sided on the hack kit side if it wasn’t for the fact I fought it for nearly 3 months straight, it adapts, it counters, it does it offline.

It’s all in public repo atm so you can go and check all the reports and all the data, with all the screenshots. But I’ll re-iterate, whilst I didn’t know linux, I could still root cause, identify patterns, and spent my whole life with computers, when I broke I’ve visage the files were all dated 10th feb. I got hacked on the 4th feb, realised the 7th, and the 10th was when the IE and cloudflare incident happened, hacker installed a payload which was all dug up in logs.

Smooth511/masterhq on github, clone is on Smooth115 knock yourself out, dig through it all but it was a rooty, it wasn’t advanced at start. It took days to even be noticeable in linux when I was using it to try clean windows. 2 months later it’s pretty good ;)

I’ll list 2 of the funniest moments, 1 when it lost the plot and posted in logs “loading paravirtulised hypervisor on bare metal “ and 2 was a few days ago, when I broke the overlay I ripped all the data I couldn’t see, used it against it all at once. Basically wrecked its persistence, it was on my nvme, thinking it was its live usb, trying to install cdrom, using drivers for hardware that didn’t exist, it ended up sigkilling all key services and the liveusb. It would always load its crash logs first thing in a boot, then wipe them. I did a number of things (all documented) but primarily sfdisked every device, fed it 32gb of grep file reading of its own data I ripped on a boing trapped crash log that it touched on load, ran a good 40 bootloader parameters, but stuff like hit it with noefi as Casper drops, tied in with hash check and no hash provided, changing its run order, killing acpi bpf. Tons more. Spent an hour rebooting just watching it kill itself over and over, in the end the bootloader just said booting efi …. With the actual boot logs loading below in the end it just stopped. All there, have fun! :)
 

Attachments

  • IMG_7025.PNG
    IMG_7025.PNG
    609.9 KB · Views: 29
  • IMG_7028.PNG
    IMG_7028.PNG
    798.7 KB · Views: 39
  • IMG_7026.PNG
    IMG_7026.PNG
    468.1 KB · Views: 36
  • IMG_7027.PNG
    IMG_7027.PNG
    485.5 KB · Views: 34
Last edited:
@CoincidentalHell wrote:
I did a number of things (all documented) but primarily sfdisked every device
One wonders what would have happened if the drives were actually fully wiped, or cleaned, or zeroed, perhaps multiple times to ensure that any code remnants on the drives were removed. Such cleaning could be done in a second machine without the drives ever being mounted. Just wondering.
 
@CoincidentalHell wrote:

One wonders what would have happened if the drives were actually fully wiped, or cleaned, or zeroed, perhaps multiple times to ensure that any code remnants on the drives were removed. Such cleaning could be done in a second machine without the drives ever being mounted. Just wondering.
 
They have been, so many times. Lost 2 hp minis that were recovery mode bots. Broke them down and use all the parts for a midway usb cleansing station / dropping files in from phone using it as a server. Morthboard short circuited in the end. They write binary on the nvme0n1 / nvme0 couple of lines, either “”hahafkefi” or stuff like that to break secure boot, or rooty feeds false info. All screenshots in reports. Spent 2 weeks doing nothing but, couldn’t clear them. Ended up time gating devices, they’d improve or learn new tricks, no point wiping till figure out the counter or fail. I was learning at same time, half of it was enjoyable, once you figure out how to beat em, on that improvement, you got time gated others that you already know what they gonna do. Honestly was same, never believed any of it, had gone 25 years either nothing but about of spyware. Now I got a 10 stage procedure just to boot on and secure the house network, kids devices, flush everything if I had to grab bits online, most of them stay offline for a week or more.
 
Remember we discussed fwupd and how the vendors shipping firmware distributed via it authenticate in anohter thread? Yes, they can. Root and a bios without available/active/effective flash write protection does it.
That is a good exception, we're talking about regular hackers who don't have any access to anyone's system by default, they need to gain root to do anything.
The other type of potential threat actors are those who we trust by default, they're ISP's, governments, software vendors etc.
People behind fwupd are not regular hackers, they're software vendors who people trust by default without thinking what they can do if they want.
 
That’s interesting cause I was looking into this 2 days ago after it got reflagged, likewise when broke the overlay, found a fair few of its versions buried away.
Remember we discussed fwupd and how the vendors shipping firmware distributed via it authenticate in anohter thread? Yes, they can. Root and a bios without available/active/effective flash write protection does it.

@Rocketing-warp9 Ring0 is not ROM but the kernel https://en.wikipedia.org/wiki/Protection_ring

"title": "Add 5-agent investigation report and update UEFI evidence with cross-platform timing findings",
"body": "5-agent review of the Linux/firmware breakthrough session (LinuxRaw pt1 & pt2) against all prior evidence. Verdict: breakthrough confirmed. CN=grub self-signed MOK cert in UEFI NVRAM is the root of trust compromise — predates current install by 7 years, zero public CT log footprint, survives every reinstall.\n\n## Changes\n\n### UEFI-MOK-KERNEL-EVIDENCE-2026-03-26.md — updated\n- Finding 8 (new): Cross-platform Day 3 / Day 19 phone-home timing correlation. Windows malware callback cadence maps exactly onto Linux-side events: kernel anchored Aug 8, VT first-seen Aug 25 (Day 17), force-complain/usr.sbin.sssd created Aug 27 (Day 19) — same day as Windows second callback. Not coincidence; confirms single-operator cross-platform operation.\n- Finding 9 (new): Kernel build string context from web research. Ubuntu using multiple lcy* build servers is normal; the same binary reporting three distinct variants (lcy82-amd64-109, lcy02-amd64-100, lcy82-amd64-100) across boots on the same machine is not. Pending hash verification on a clean machine.\n- Cumulative findings table: rows 17 (timing correlation) and 18 (VT first-seen anomaly) added.\n- Security assessment: kernel build string entry updated to reflect web-research nuance — build server variation is explained, three-variant anomaly from one binary is not.\n\n### INVESTIGATION-REPORT-2026-03-26-5AGENT-REVIEW.md — new file\nFull 10-part report covering:\n- Claim-by-claim verification of the breakthrough (confirmed / partially confirmed / unconfirmed)\n- Cross-references to MASTER_REPORT (Windows), MK2 Log Analysis (live USB), and history timeline\n- Cross-platform scope: Windows + Linux + iOS — same operator, same callback schedule, firmware bridge via MOK cert\n- What previous agents missed (ACPI conflicts dismissed, fwupd smokescreen misread, cloud sync suggested)\n- Prioritised course of action: immediate (NVRAM hexdump, hash verification, DSDT dump), short-term (BIOS flash, NVRAM clear), medium-term (hardware replacement criteria, iOS forensics, network monitoring)\n- Full evidence hash table and open questions\n\n## Key finding not previously documented\n\nThe sssd AppArmor weakening timestamp (force-complain/usr.sbin.sssd, Aug 27 2024) lands on exactly Day 19 of the operation timeline — the same interval as the Windows phone-home callback documented in MASTER_REPORT. This connects both investigations to a single operator and a single deployment window.",
"base": {


…- What previous agents missed (ACPI conflicts dismissed, fwupd smokescreen misread, cloud sync suggested)\n- Prioritis…
…31 07:00, systemd symlink Apr 19 15:24\n - [x] Image 2: fwupd Aug 8 17:17 (firmware write window), phantom mic card0.…

I noticed a recurring pattern when things escalated day 3 19 and 27 I think it was. Identified March. When we found the MOK certificate during that report and hashed it, it wasn’t offical but had first appeared online exactly that amount of days after the data I dug out comp. These files and logs constantly get regenerated or appear on a oom, looks like whatever this is was created August 8th. Got reflagged because:

 
Now for the part that makes me sound like a raving looney. When I posted here last week “counter fact checked from other sources. Those reports had nothing on the actual, we were convinced it was vtoy and ventoy avenue but no, I found it, all, beat it. Then it came back lol”
well it turns out we were right nearly 2 months ago. It is Ventoy / Vtoy, but not in the way you would imagine so I will give this an apt finale title.

Me, Rooty, and the Ventoy Rootkit Factory

Back in March, I intentionally crashed a windows install at 49%, caught rooty in a handover, got files and data that had been stolen + discovered the Dism and restart button hooks. There was ventoy files, that we eventually dismissed start of this month- we’d followed the whole chain through every script and process and landed in a live environment during the vtoy handover to init, and it was all “clean”.

4 days ago I found a bread comb, a needle in the haystack that suddenly clicked. At the end a Ventoy language .json a simple line “MENU_STR__XXX “” “. Tldr this segment was the final link that leads all the way back to windows, and the multiple infections. It to me was like I can’t explain it, I can’t prove the process chain in a way to make others believe it, I suppose the best way to explain this whole saga is “I can grok it” . That one single line and suddenly I could see it all. Now if you thought this story was bull*** and I’ve lost my marbles, probably best you stop reading here cause this is about to go supernova on the bull***’o’meter.

I have spent more time than you can imagine digging and sifting - for example linux on my 2nd install, I left an account afk in journalctl with every setting on debug, full verbose, whatever for 6 days. I then spent 4 days going through it, line by line, questioning everything I didn’t understand. Can’t explain any of it to you, but I can read code and see what’s happening.

In the windows hacks, and rootkit infections, permissions hyjack it always came back to null SIDs. 1-[5-11]-[x-18] -XXX-XXX-XXX mostly or completely 000. The same permissions hyjack was being applied in linux. Through live session user, root backdoors the usual shit - with one major difference will cover later.

As I visualised it all as it became clear, I just laughed to myself, through this whole saga I’ve been banned from most forums, laughed at by the big AV communities, the cyber security groups, labelled a malware creator , you name it, and it all comes down to - how do you prove something you can’t explain, and can’t provide proof because for all intents and purposes, my files are clean. I’ve been in a hypervisor bubble for months, anything I get close to is scrubbed or corrupted. Except I’d seen it, and was piecing it together. Story time over; this is all the truth, most of it is logged, all aboard crazytown express. (Everything below is logged in some shape or form on github)

—————————————————-

I made a treaty with the rootkit .
I’d corrupted its persistence beyond a level it couldn’t fix, a simple nano and text editor exchange. It left me alone it could have the internet.

Fresh install, no interference, hard part done. I’d told “it” it could have its own hd and thus mounted my 1TB nvme, on my 250gb nvme. Created a user through user admin software” mint” plugged 2 cables into gfx card - hdmi and dp. Set up 2 seats, then hit the dd copy Iso. Praying it worked. Hook, line, sinker and then it happened. Firefox loaded, dictionary popped up, files loading from here there and everywhere, all changing into Chinese, (not connected to internet yet) and then a the cpu go brrrr and it was on its seat. And it hadn’t noticed I secretly logged it for 36 hours, hdmi ran to my capture card, it had masked the Ethernet from lo / eth0-1 to enp[3-5]sO, changed the nvidia drivers to run as nouveau as it always did, remapped all the bios and acpi as it always did, it masked everything I wanted hid, for me , during the install using its own injected installer.

It always changes the Ethernet, first thing it does and pretty sure that’s where it s mainly bound.

Plugged net in, and for 36 hours we co-existed, it never interferred, I never directly provoked. (Comp was completely clean, kids were away, nothing connected with any data) 36 hours later, I had what I needed, and all hell broke loose.

I had the overlay setup, I’d seen it self installing and configuring and then deactivating on its new drive. Hit a kernel update to get the restart I needed, computer slowed to a crawl root was watching, reset, ripped hdmi and dp out, screwdrivered CTRL pins 10s later straight into bios, cpus from 8>2. EVERY setting nuked. All system monitors off, all virtualization cancelled save profile usb, ripped usb and ctrl alt del. In to linux, deleted usr mint, remounted everything it would need to get in ro and began the nuke town on 207 identified and primary targets..

First screenshot is the culmination of logging and iding. (So you believe me ) This thing had stuff I didn’t know existed, and simple stuff like mtools to steal my stuff, getting into grub bootloader same time as me through serial, terminal in out, console and xnu.

Took out everything accessibility / logging / input, if it had used it the last 36 hours, I nuked it. Then mount em ro with mount syml to null and chattr empty dir. then systematically nuked triggers > hooks > caches > dupe bin dumps > source lists. Install>reinstall -confless apparmor, apt, dpkg, systemd, pam, >nuke samba /accountservice/ Active Directory> reconfig / reauth Pam and sudo backdoors > nuke local cdroms > hidden “floppies” > configs . Dpkg —purge —force-all on anything when dependency overlaps came in. Rooty was getting close, cpu was about to liftoff and fly into space, could feel the heat .

I didn’t manage to kill it all before it got in, I’d missed something because audit logs exploded, errors streaming at speed of light. Force remounted the whole drives rw, synced, attempted to force unmount everything but it was latching everything, so hit the last stage, a decrypt delete on the one thing that mattered the most the ./ bubble id lived in for months, saw the key drop and a corruption error. Deleted key. Synced, attempted another full umount, nada. REISUB, rip nvmes out, CMOs out, cable out, drain.

And that is how I put the rootkit in an overlay, of an overlay, in what I called cow-ception (an a4 contains the basics ) part 2 coming up, the battle of the bios, rooty destruction and the ventoy rootkit factory.
 

Attachments

  • IMG_7424.jpeg
    IMG_7424.jpeg
    311.4 KB · Views: 24
  • IMG_7179.jpeg
    IMG_7179.jpeg
    342.5 KB · Views: 32
  • IMG_7180.jpeg
    IMG_7180.jpeg
    295.4 KB · Views: 31
  • IMG_7177.jpeg
    IMG_7177.jpeg
    379.7 KB · Views: 31
  • IMG_7174.jpeg
    IMG_7174.jpeg
    397.8 KB · Views: 33
  • IMG_7172.jpeg
    IMG_7172.jpeg
    228.8 KB · Views: 26
Part 2 battle of the bios

Was scared to turn the computer on tbh, had it worked, was the light at the end of the tunnel? Tldr; no. And Rooty Tooty had gone Karenzilla mode.

Network flushed and reset, in clear nvram with optimized, clear sb and tpm keys. (2 fresh ram sticks in, no gfx card, no hd, no usbs other than mouse and keyboard, no memory on em) no bt or WiFi. Set password. Save restart. In, confirm changes went live, re-run whole process on a CMOS clear. Sb tpm up, restart, new live usb in, in to ventoy, iso1 > iso menu > bootloader > iso > advanced e > “insmod ext2, insmod part_gpt cxxxxx” ls (proc) (memdisk) (hd0msdos1) (hdmsdos2) (hd0) (hd1) ls mod “list of 80 mods”. Fuck.

Try/install > graphical (xf4ce) > user mint(live session user) auto login. > adduser terminal. Denied. User Admin (software) no permissions to do that. Apps disappearing at speed of light. Terminal > purge xxxxxxxx 50 key items, freezing at 20-30% unfreeze 30s later with failed to remove. GUI disappeared, keyboard and mouse lost power. Frozen screen.

it was at this point I knew I was fucked, lol.

Spent an hour getting into pre-init breaks and cleaning binary off injected drives, then after afew hours managed to override permissions in no root break, strip live user perms in rw recovery without kernel panic on jump to live, and got in running the official installer backdoor link bypassing its injection and added extras. (At this point computer was packing in, the cpu throttle was working, and preventing everything it does in background)

Ripped at installation complete, crashed instance, new live USB nvme on no boot, ro, into graphical, mount boot rw, umount, repair boot nvme. Reboot, clean process, nvmedrive in, time for the bootloader from hell. Init.blacklist=gcc gnu xnu sudo virtual serial + 20 others. Block everything imaginable, no modules, no kernel changes, full auditing and logging (hog cpu). In looks pretty good, 15-20 minutes examining, then as I type a cd it errors some crap about Rrrshevh wtf. Next thing I know I can’t type nothing coherent, smashing ctrl c ctrl backspace ctrl q reset screen, tried changing console or sh nada. Fk it magic ctrl k. Headshot 111 user Ubuntu , followed by kernel panic. Bollocks.

Restart go again, bootloader. Speed of light set loader f10, land at graphical emergency mode, please enter root password. Ctrl D, login graphical. Mint. Defaults ain’t working it had done me. Restart bootloader, tried killing mods, clearing its backdoors, then my nvmes shut down.

The fkin thing was no shutting down nvmes . No usbs would detect anything new, it killed any that were in, killed drives, I couldn’t save or boot. 3-4x attempts, counters same result couldn’t even get the boot loaded in (didn’t wanna live usb now and feed it all the isos / mounts they had) got annoyed so smashed f10 few times and noticed gfxterm / video serial numbers had gone up. Smashed f10 some more, more instances. Likewise in ls lo and behold (memdisk) (proc) (hd0)(hd1) all still there but my hd0,gpt1-2s gone. It was karenzilla. Bootloader modprobe all ls. Mod probe /dev and 10x boot commands wrapped in echo of echo of echo. Screwdriver in keyboard holding f10 down. And at around 30k gfxterm and font count everything started proper glitching. The overlay vt was packing in, and then crash. Restarted, bios needs setup. Hmmm

The Bios

It was now resetting the bios settings, turning fast boot on, turning cstates on, after 2 attempts, I got it locked in, restarted, it had changed my password. Tried discard to boot, restarted, 3x quick restarts, it had disabled secureboot. Luckily I can clear with cmos, went in crash. Freezing screens, everything else. Powered down, drained. Went again recording. 15 minute video, catch it live changing my password, catch it live when I break its mok signing certificate and the moment I find why. I’d broken the overlay, this was its last ditch attempt to hold on. 3 screenshots from video. Pw going installed 1s later. Video has it all. The mok certificate failure after bootloader overload, it couldn’t function it was full . Spent another hour corrupting it through bootloader and settings, stuff like loading tons of mods booting and instantly ripping power out, it started posting gibberish in logs.

FREEDOM

Eventually I let it boot, I’d left it with admin control over bios at this point I just unplugged my keyboard each boot and it’d stay on bios screen login until I got the timing down right hahahahha. Plug kb back in before hit bootloader, change some parameters, go again. Eventually made it to graphical and it was peaceful, quiet, and I saw what a real install looks like. I had access to settings I could only dream of lmao. Hooked the net up, data dumped github and gave the lads the whole 1TB nvme rooty had owned for 36 hours and let em rip it to shreds. Went straight for the ventoy partitions on live usbs and any drives that were still bootable, ripped the lot and secured it. Worked with agents for 1-2 days. Collated everything including the old data what was left of it (I’d lost a whole github by this point - my original was my 16 repository LLM id created with custom framework) I’d moved it locally and began training agents and process (all verbal, couldn’t code for shit hahaha) but that was lost along with most the original data on the bitlocker attacks 10thfeb-28thfeb, along with all my personal data and 60 gb of every family photo from last 15 years. Might help explain why I ain’t stopped.

Now over the last 3 months I’ve collected everything, 4000+ photos, data dumps are huge, half the data dump AI dives I had done I’ve never posted. But throughout the whole thing everytime I’d killed one of these fkers I’d get a snippet of custom code, a new lead or point of interest around what was happening, and in this rip contained the last piece, rooty had dropped the final 40 page script that I could apply everything else I had to, the XXX str was the key, the link to unreavelling the rest. And eventually I figured out the key. A very specific key sequence, combined with sequence of events, and precise order to unhide the overlay over ventoy if you will, the unlock that turns the ventoy loader and customiser into the fully functional rootkit factory. It allows injecting and customising of any iso, stores bios and every key data you need, contains all the overrides, the settings for what it should do, the themes and how to setup them up so the user never knows. It contains .imgs and how they are stored, all the major cves, versions, how to inject the vulnerabilities into any iso and then merge them into rooty so it’s updated by still able to bypass.

It’s all in Chinese, I’m halfway there, I won’t be detailing the process, but I’m proving concept by creating my own, gonna see if I can configure rootyMKII into karenzilla killer and free my devices for good. Probably won’t end well, never does, but I’m having fun. ::I accept no responsibility or liability in the event a rootkit called karenzilla becomes a problem::

For now, enjoy the screenshots and thanks for interacting, the only place I didn’t get banned and people actually spoke to me, lmao. Hope you enjoyed folks, it’s been a long 3 months and I’m nearly rootkit free, but at least it’s not living rent free now!

The last screenshot contains a windows iso. Within this program is another, along with 6 unattended .xml documents. One of the first things I found was reference to it, it’s the payload, the first contact and the wrapper to unpack this monstrosity. The self updating, generative rootkit, that works on windows and linux, and laterally moves across both + network. I might eventually prove this was also what infected my phone (iPhone 14) as have most the proof, but for now I’m gonna remove this bastard and see what a real linux install looks like !
IMG_7394.jpeg
IMG_7430.png
IMG_7429.png
IMG_7428.png
 

Attachments

  • IMG_7400.jpeg
    IMG_7400.jpeg
    452.2 KB · Views: 28
  • IMG_7398.jpeg
    IMG_7398.jpeg
    306.9 KB · Views: 30
  • IMG_7396.jpeg
    IMG_7396.jpeg
    349.7 KB · Views: 35
  • IMG_7401.jpeg
    IMG_7401.jpeg
    331.2 KB · Views: 26
  • IMG_7405.jpeg
    IMG_7405.jpeg
    484.1 KB · Views: 30
  • IMG_7406.jpeg
    IMG_7406.jpeg
    513.7 KB · Views: 31
  • IMG_7418.jpeg
    IMG_7418.jpeg
    165.2 KB · Views: 29
  • IMG_7404.jpeg
    IMG_7404.jpeg
    211.6 KB · Views: 23
  • IMG_7411.jpeg
    IMG_7411.jpeg
    213.9 KB · Views: 24
  • IMG_7423.jpeg
    IMG_7423.jpeg
    260.2 KB · Views: 30
  • IMG_7416.jpeg
    IMG_7416.jpeg
    396.2 KB · Views: 27
  • IMG_7413.jpeg
    IMG_7413.jpeg
    370.8 KB · Views: 27
Turns out you actually need to be able to code to do that stuff LOL. On planb atm. Following cowception and utilising multiple fedora bluesilver installs - the rootkit locks the drives at nvme0 layer as a iso9960 so been playing with changing things in an overlay of an overlay of an overlay and changing which are ro rw dropping in before anything initialises. This is what it does for example: this nvme drive had a mint install, I cp a fedora iso on to it, that I then used to install onto multiple devices.

But trying to run that actual iso and very weird things started happening - hd0, hd0,gpt1 hd0gpt2 all contain boots and efi. gpt3 god knows. Look at the part uuid though hahaha.

So I’m attempting to mount the nvme, within the fedora usb install, because fedora has override until that initializes. Lockdown =none break=mount init=/bin/sh see if I can wipe the devices of its hard lock ro and then go from there. This is where any knowledgeable people - any tips or guidance much appreciated. Did try fedora bluesy clean usb, rooty hooked and fked it before I even managed to log in, I had no rpm, hyjacked apps , it couldn’t change any of my immutable stuff but I had nothing to do anything, went online, it was all failing so pulled plug and went this route.
 

Attachments

  • IMG_7632.jpeg
    IMG_7632.jpeg
    1.5 MB · Views: 37
  • IMG_7634.jpeg
    IMG_7634.jpeg
    1.6 MB · Views: 33
  • IMG_7635.jpeg
    IMG_7635.jpeg
    583.6 KB · Views: 28
Nope not a story digging through it atm where it mounted dm-0 onto /etc so remapped to /sysroot and can edit so yeah digging through now
Still, I fail to decipher anything useful from your barrage of posts. You are yet to convince me of anything. To my eye, you have no rootkit whatsoever. Prove me wrong please.
 
Last edited:
You need to reevaluate everything from within a Faraday Cage, my friend.

Did you know some malware can spread via speakers? There are all kinds of side channel attacks. Unless you're examining this stuff from a properly shielded clean room, anything goes.
 
This is what it does for example: this nvme drive had a mint install, I cp a fedora iso on to it, that I then used to install onto multiple devices.
Depending on how you write an ISO image to a device (usb or ssd), it will indeed result in an immutable ISO9660 filesystem. That's by design of the filesystem itself and has nothing to do with anything else per se.

If you can boot the fedora image from USB, just do that. You don't need to mess with the uefi console, but can use the live image tools to wipe the nvme.
 
You need to reevaluate everything from within a Faraday Cage, my friend.

Did you know some malware can spread via speakers? There are all kinds of side channel attacks. Unless you're examining this stuff from a properly shielded clean room, anything goes.
Yes finding ipp-usb along with others and it had written configs and updated rules to start using it, only found it because I logged some data transfer over network and was well and truly confused as it ain’t allowed anywhere near an Ethernet. Reminds me of the start when I left it running and few days later one of my usbs was registering as a floppy disk.
 


Follow Linux.org

Staff online

Members online


Top