logo

'RingReaper' Sneaks Right Past Linux EDRs

ID: 63105d14-d840-5f12-bcc9-177c3ab64f69

STIX ID: report--63105d14-d840-5f12-bcc9-177c3ab64f69

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

RingReaper is a sophisticated post-exploitation Linux implant that leverages the kernel's io_uring asynchronous I/O interface to bypass EDR syscall hooks, perform process and network discovery, collect data, escalate privileges, and self-destruct; Picus Security's analysis indicates this is an advanced evasion technique targeting enterprise and cloud Linux workloads and recommends monitoring io_uring-related syscalls and restricting its use where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.