RingReaper Linux Malware: EDR Evasion Tactics and Technical Analysis
ID: 489ffea2-1bba-5c3f-b8c5-f99f70ab66f7
STIX ID: report--489ffea2-1bba-5c3f-b8c5-f99f70ab66f7
Feed Name: Resources-2
Date Published: 2025-08-14
Date Updated: 2026-07-22
Author: [email protected] (Sıla Özeren Hacıoğlu)
RingReaper is a sophisticated Linux post-exploitation agent that abuses the io_uring asynchronous I/O interface to stealthily perform process, network, and user discovery, local data collection, privilege-escalation checks, and self-deletion. The report maps these behaviors to MITRE ATT&CK techniques (e.g., T1057, T1049, T1033, T1005, T1068, T1564), enumerates observed payload filenames (such as $WORKDIR/cmdMe, executePs, loggedUsers, netstatConnections, fileRead, privescChecker, selfDestruct), and provides detection opportunities and mitigation guidance for EDRs and defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
