logo

Linux Injector for automated malware analysis

ID: 81e8f360-a233-5a04-b5b2-f47fd7bff8ff

STIX ID: report--81e8f360-a233-5a04-b5b2-f47fd7bff8ff

Feed Name: CERT Polska

Date Published: 2021-08-20

Date Updated: 2026-04-19

Author: Manorit Chawdhry

...
...

This post summarizes a Google Summer of Code effort to redesign Drakvuf’s Linux injector for automated malware analysis at scale, shifting from unstable glibc-based methods to direct syscalls executed via vDSO-located syscall instructions in a hijacked user process. It explains the trap-and-breakpoint workflow, how vDSO is located and used, and the implementation of write-file and read-file methods to transfer files between host and guest. The work establishes a foundation for a future exec-file method to fully automate Linux sample execution in VMI-based environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.