Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Linux Rootkits Leverage Advanced eBPF and io_uring Techniques for Stealthy Attacks

## Cybersecurity: Advancements in Linux Rootkits

Cybersecurity: Advancements in Linux Rootkits

Linux rootkits, historically less scrutinized than those for Windows, have become increasingly significant with the rise of Linux in cloud infrastructure, containers, and IoT devices. These developments have altered the threat landscape, necessitating a focus on evolving security measures.

Over the past two decades, Linux rootkits have significantly advanced. Initially relying on detectable methods such as userland shared object injections or Loadable Kernel Modules (LKMs), modern rootkits now utilize sophisticated techniques for concealment.

Security researchers have observed that contemporary Linux rootkits exploit legitimate kernel interfaces like eBPF and io_uring. These advanced methods enable unprecedented stealth, persistence, and evasion from Endpoint Detection and Response (EDR) systems.

As enterprises adopt Secure Boot, module signing, and strict kernel lockdown policies, traditional kernel-space rootkits face increased detection. Consequently, attackers have shifted towards using built-in kernel features intended for performance and tracing as methods to subvert the operating system.

The Shift to eBPF for Undetectable Execution

The extended Berkeley Packet Filter (eBPF), initially designed for packet filtering and kernel tracing, has evolved into a robust in-kernel virtual machine since Linux kernel version 4.8. eBPF allows the execution of bytecode within the kernel without requiring custom modules or kernel source code modifications.

These developments have altered the threat landscape, necessitating a focus on evolving security measures.
Sean Avery · Thehackingpost

Malicious actors have leveraged eBPF to attach hidden code to system call hooks, tracepoints, or Linux Security Module (LSM) events. This technique bypasses traditional LKM scanners like rkhunter or chkrootkit and avoids Secure Boot restrictions, as it does not necessitate out-of-tree module loading.

Notable examples include tools like TripleCross, which hooks system calls using eBPF, and Boopkit, which utilizes eBPF for covert command-and-control operations.

Attackers have also exploited io_uring for evasion. Introduced in Linux 5.1, io_uring is an asynchronous I/O interface that enables the batching of multiple system operations through shared memory rings. While designed to reduce system call performance overhead, this feature also aids in evasion.

Advertisement

By employing io_uring_enter for processing multiple operations, rootkits minimize observable system call events, thereby evading traditional EDR solutions that depend on individual system call interception. Rootkits like RingReaper demonstrate how attackers can replace common system calls stealthily using io_uring .

These advancements in rootkit techniques underscore the necessity for security teams to develop new low-level monitoring strategies as Linux increasingly dominates enterprise and cloud environments.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories