logo

Detecting and Mitigating io_uring Abuse for Malware Evasion

ID: fcab846f-ee48-5b4d-aad9-6f156bf72889

STIX ID: report--fcab846f-ee48-5b4d-aad9-6f156bf72889

Feed Name: Sysdig Blog

Threat Score
50/100

Date Published: 2025-04-25

Date Updated: 2026-05-01

...
...

On April 24, 2025 ARMO published a proof-of-concept called "curing" that uses Linux io_uring to evade many system-call-based security products; Sysdig explains the technique, its limitations (requires prior access and does not hide files/processes), and publishes a "Suspicious io_uring Activity Detected" rule while Falco will add detections using kernel runtime instrumentation; recommendations include layered defenses, cautious seccomp adjustments, and reliance on FANOTIFY-based detections which remain effective.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.