FlipSwitch: a Novel Syscall Hooking Technique
ID: ec4c2546-aad8-57ad-9485-a1714f7521ef
STIX ID: report--ec4c2546-aad8-57ad-9485-a1714f7521ef
Feed Name: Elastic Security Labs
Threat Score
FlipSwitch is a technical proof-of-concept rootkit technique that defeats Linux kernel 6.9's switch-based syscall dispatcher by locating the compiled call instruction to a target syscall (using sys_call_table/kallsyms via kprobes), disabling CR0 write protection, and patching the call's relative offset to redirect execution to attacker-controlled code; the report includes example kernel code and a YARA rule for detecting the PoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
