An (incomplete) Linux-based user-land rootkit developed for understanding of how rootkits work and how to protect against them. It works by hooking PAM (Pluggable Authentication Modules), but was destined to also hook pcap and the likes.
NOTE: I actually started a new rootkit from scratch (2018), which is far better/beyond in terms of code and overall functionality. However, due to the functionality, I do not wish to publicize the code.