Singularity Linux Kernel Rootkit with New Feature Prevents Detection
ID: bbf68920-8ec3-5f0e-bf87-03441fb6f889
STIX ID: report--bbf68920-8ec3-5f0e-bf87-03441fb6f889
Feed Name: cybersecurityNews.com
**Singularity** is a sophisticated Linux kernel rootkit (LKM) targeting Linux 6.x that leverages ftrace-based syscall hooking to provide deep stealth and persistent root access. It can hide processes, files, and network connections, uses an ICMP-triggered reverse shell for covert C2, sanitizes logs and clears kernel taint to evade forensics, and includes mechanisms to block eBPF-based monitoring and other kernel protections—posing a high-risk threat to Linux deployments despite no evidence in this report of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
