Honeypot capture

rootpacket

VT 29/74CVE-2026-31431

Escalation comes from getroot, a working exploit for CVE-2026-31431, an AF_ALG page-cache LPE that also escapes containers to the host. What it escalates into is ordinary cryptojacking: an intel_uncore_freq_aux LKM rootkit that fakes CPU and memory and rebuilds itself through DKMS, a UPX-packed XMRig, and a rival-killer.

Family
rootpacket
First seen
June 2026
Vector
Docker API → privileged-container host escape
Format
~5 MB toolkit archive (Linux)
VirusTotal
29 engines: trojan.abtrojan/gen2
Tags
cryptominer · rootkit · lpe · container-escape · docker · cve-2026-31431
Report
A Linux cryptojacking toolkit that hides in the kernel
Sample
Public GitHub repo

SHA-256

  • e2d0dab6b29df89d123fe8581047a03ac9b89ae8fa0d1f334b5aefbb93152857 toolkit archive
  • dda96d8a4bcc39dc7679347a4386bf1024152d2ccc46d333725ad0cda855d952 getroot, the working CVE-2026-31431 LPE

The public repo carries getroot, a working local-root exploit. Detonate only in an isolated, disposable VM with no network path to anything you value.

← All captures