logo

Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection

ID: 4c04f55c-3f30-5403-b739-9c137a0fb4d7

STIX ID: report--4c04f55c-3f30-5403-b739-9c137a0fb4d7

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-09-02

Date Updated: 2026-09-11

Author: Divya

...
...

A security researcher disclosed that the Singularity Linux rootkit can bypass Elastic Defend by dynamically registering its loader as a trusted process in the agent's BPF map to suppress module-load events, placing generated kernel objects in DKMS-related paths to evade build-path exclusions, obfuscating module source to reduce YARA detections, and hiding modules from standard kernel interfaces; tests on Elastic Defend 9.5.2 demonstrated this evasion and the report recommends hardening protections around BPF maps, correlating module-load telemetry with kernel integrity signals, auditing finit_module and related syscalls, and avoiding blanket exclusions for build paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.