How does this “stealthy Linux rootkit” get onto the system in the first place. Without opening a malicious email attachment or clicking on a malicious weblink.
Now that it's at least 2 years after the initial intrusion, it could be pretty tough to determine how that happened and what path the attacker took.
Behind that are attacks on Linux web servers where exploits in the web application (e.g. WordPress) or the web framework (e.g. Rails) are the attack vector.
The email attachment may come from your friend/business partner which themselves got infected and the malware is now attaching itself to their legit emails. (AFAIK not very common)
EDIT: from the article:
The researchers have so far been unable
to determine precisely how Krasue gets
installed. Possible infection vectors
include through vulnerability
exploitation, credential-stealing or
-guessing attacks, or by unwittingly
being installed as trojan stashed in an
installation file or update
masquerading as legitimate software