Linux Injector for automated malware analysis
ID: 81e8f360-a233-5a04-b5b2-f47fd7bff8ff
STIX ID: report--81e8f360-a233-5a04-b5b2-f47fd7bff8ff
Feed Name: CERT Polska
This post summarizes a Google Summer of Code effort to redesign Drakvuf’s Linux injector for automated malware analysis at scale, shifting from unstable glibc-based methods to direct syscalls executed via vDSO-located syscall instructions in a hijacked user process. It explains the trap-and-breakpoint workflow, how vDSO is located and used, and the implementation of write-file and read-file methods to transfer files between host and guest. The work establishes a foundation for a future exec-file method to fully automate Linux sample execution in VMI-based environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
