PoC rootkit Curing evades traditional Linux detection systems
ID: e7d7c62f-ce9d-53fb-9f76-d88269544ac7
STIX ID: report--e7d7c62f-ce9d-53fb-9f76-d88269544ac7
Feed Name: Security Affairs
Armo researchers published a proof-of-concept rootkit called Curing that abuses Linux's io_uring asynchronous I/O to perform network and filesystem operations without making traditional syscalls, rendering syscall-based monitoring ineffective. The report demonstrates C2 communication and multiple malicious actions, provides PoC code and vendor testing results (many tools missed activity while some detected/mitigated it), and recommends detection improvements such as LSM hooks and careful eBPF placement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
