logo

RingReaper Linux Malware: EDR Evasion Tactics and Technical Analysis

ID: 489ffea2-1bba-5c3f-b8c5-f99f70ab66f7

STIX ID: report--489ffea2-1bba-5c3f-b8c5-f99f70ab66f7

Feed Name: Resources-2

Threat Score
70/100

Date Published: 2025-08-14

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

RingReaper is a sophisticated Linux post-exploitation agent that abuses the io_uring asynchronous I/O interface to stealthily perform process, network, and user discovery, local data collection, privilege-escalation checks, and self-deletion. The report maps these behaviors to MITRE ATT&CK techniques (e.g., T1057, T1049, T1033, T1005, T1068, T1564), enumerates observed payload filenames (such as $WORKDIR/cmdMe, executePs, loggedUsers, netstatConnections, fileRead, privescChecker, selfDestruct), and provides detection opportunities and mitigation guidance for EDRs and defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.