Honeypot capture
rootpacket
VT 29/74CVE-2026-31431
Escalation comes from getroot, a working exploit for CVE-2026-31431, an AF_ALG page-cache LPE that also escapes containers to the host. What it escalates into is ordinary cryptojacking: an intel_uncore_freq_aux LKM rootkit that fakes CPU and memory and rebuilds itself through DKMS, a UPX-packed XMRig, and a rival-killer.
- Family
- rootpacket
- First seen
- June 2026
- Vector
- Docker API → privileged-container host escape
- Format
- ~5 MB toolkit archive (Linux)
- VirusTotal
- 29 engines: trojan.abtrojan/gen2
- Tags
- cryptominer · rootkit · lpe · container-escape · docker · cve-2026-31431
- Report
- A Linux cryptojacking toolkit that hides in the kernel
- Sample
- Public GitHub repo
SHA-256
-
e2d0dab6b29df89d123fe8581047a03ac9b89ae8fa0d1f334b5aefbb93152857toolkit archive -
dda96d8a4bcc39dc7679347a4386bf1024152d2ccc46d333725ad0cda855d952getroot, the working CVE-2026-31431 LPE
The public repo carries getroot, a working local-root exploit. Detonate only in an isolated, disposable VM with no network path to anything you value.