logo

Watch out for any Linux malware sneakily evading syscall-watching antivirus

ID: 03262e27-dc2c-510b-aa9a-322e0e5bd2c5

STIX ID: report--03262e27-dc2c-510b-aa9a-322e0e5bd2c5

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-04-29

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

ARMO released a proof-of-concept named Curing that abuses the Linux io_uring interface to perform file I/O without traditional syscalls, allowing it to evade syscall-based endpoint protection (Falco, Tetragon and reportedly Microsoft Defender in default configurations). The report details vendor responses, mitigation options (disable io_uring or implement kernel-level monitoring/eBPF), and provides links to the POC and additional guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.