Singularity: A Stealthy Linux Kernel Rootkit for Modern 6.x Kernels
By
matheuzsec
An everything bagel for the brain. Substantive, layered, well-seasoned.
Summary
Singularity is a sophisticated Linux Kernel Module (LKM) rootkit designed for modern 6.x kernels that provides comprehensive stealth capabilities through advanced system call hooking via ftrace infrastructure. The article presents it as a proof-of-concept for security research, demonstrating how it can evade endpoint detection and response (EDR) systems like Elastic EDR. It includes technical details about its features, installation, and capabilities for maintaining persistence and hiding malicious activities at the kernel level.
Key quotes
· 5 pulledSingularity is a powerful Linux Kernel Module (LKM) rootkit designed for modern 6.x kernels.
It provides comprehensive stealth capabilities through advanced system call hooking via ftrace infrastructure.
Singularity is a sophisticated rootkit that operates at the kernel level.
EDR Evasion Case Study: Bypassing Elastic EDR with Singularity
Shall we give forensics a little work?
You might also wanna read
Understanding the Orthogonal Relationship Between Memory Safety and Sandboxing in Linux Security
The article discusses the relationship between memory safety and sandboxing in Linux security, explaining that they are orthogonal concepts
Security Analysis: Exploiting Kernel Stack Use-After-Free Vulnerabilities in NVIDIA's Linux GPU Drivers
This technical article details two critical security vulnerabilities discovered in NVIDIA's Linux Open GPU Kernel Modules - specifically a k
North Korean Chollima Group Targets PHP Developers via Malicious Packagist Package
A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
AI-assisted vulnerability discovery raises concerns about Linux kernel security
This opinion article discusses a troubling trend in Linux security where AI-powered tools are being used to discover and exploit kernel vuln
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor
