Detecting and Mitigating io_uring Abuse for Malware Evasion
ID: fcab846f-ee48-5b4d-aad9-6f156bf72889
STIX ID: report--fcab846f-ee48-5b4d-aad9-6f156bf72889
Feed Name: Sysdig Blog
On April 24, 2025 ARMO published a proof-of-concept called "curing" that uses Linux io_uring to evade many system-call-based security products; Sysdig explains the technique, its limitations (requires prior access and does not hide files/processes), and publishes a "Suspicious io_uring Activity Detected" rule while Falco will add detections using kernel runtime instrumentation; recommendations include layered defenses, cautious seccomp adjustments, and reliance on FANOTIFY-based detections which remain effective.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
