All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Singularity: A Stealthy Linux Kernel Rootkit for Modern 6.x Kernels

By

matheuzsec

4mo ago· 9 min readenCode

Summary

Singularity is a sophisticated Linux Kernel Module (LKM) rootkit designed for modern 6.x kernels that provides comprehensive stealth capabilities through advanced system call hooking via ftrace infrastructure. The article presents it as a proof-of-concept for security research, demonstrating how it can evade endpoint detection and response (EDR) systems like Elastic EDR. It includes technical details about its features, installation, and capabilities for maintaining persistence and hiding malicious activities at the kernel level.

Key quotes

· 5 pulled
Singularity is a powerful Linux Kernel Module (LKM) rootkit designed for modern 6.x kernels.
It provides comprehensive stealth capabilities through advanced system call hooking via ftrace infrastructure.
Singularity is a sophisticated rootkit that operates at the kernel level.
EDR Evasion Case Study: Bypassing Elastic EDR with Singularity
Shall we give forensics a little work?
Snippet from the RSS feed
Stealthy Linux Kernel Rootkit for modern kernels (6x) - MatheuZSecurity/Singularity

You might also wanna read

Understanding the Orthogonal Relationship Between Memory Safety and Sandboxing in Linux Security

The article discusses the relationship between memory safety and sandboxing in Linux security, explaining that they are orthogonal concepts

fil-c.org·5mo ago

Security Analysis: Exploiting Kernel Stack Use-After-Free Vulnerabilities in NVIDIA's Linux GPU Drivers

This technical article details two critical security vulnerabilities discovered in NVIDIA's Linux Open GPU Kernel Modules - specifically a k

blog.quarkslab.com·7mo ago

North Korean Chollima Group Targets PHP Developers via Malicious Packagist Package

A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur

socket.dev·5h ago

Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware

Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

microsoft.com·18h ago

AI-assisted vulnerability discovery raises concerns about Linux kernel security

This opinion article discusses a troubling trend in Linux security where AI-powered tools are being used to discover and exploit kernel vuln

theregister.com·1d ago

npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads

An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor

theregister.com·1d ago