'RingReaper' Sneaks Right Past Linux EDRs
ID: 63105d14-d840-5f12-bcc9-177c3ab64f69
STIX ID: report--63105d14-d840-5f12-bcc9-177c3ab64f69
Feed Name: Dark Reading
Threat Score
RingReaper is a sophisticated post-exploitation Linux implant that leverages the kernel's io_uring asynchronous I/O interface to bypass EDR syscall hooks, perform process and network discovery, collect data, escalate privileges, and self-destruct; Picus Security's analysis indicates this is an advanced evasion technique targeting enterprise and cloud Linux workloads and recommends monitoring io_uring-related syscalls and restricting its use where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
