Watch out for any Linux malware sneakily evading syscall-watching antivirus
ID: 03262e27-dc2c-510b-aa9a-322e0e5bd2c5
STIX ID: report--03262e27-dc2c-510b-aa9a-322e0e5bd2c5
Feed Name: The Register (Security)
Threat Score
ARMO released a proof-of-concept named Curing that abuses the Linux io_uring interface to perform file I/O without traditional syscalls, allowing it to evade syscall-based endpoint protection (Falco, Tetragon and reportedly Microsoft Defender in default configurations). The report details vendor responses, mitigation options (disable io_uring or implement kernel-level monitoring/eBPF), and provides links to the POC and additional guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
