Stealthy open-source linux rootkit
by netexec - Friday January 23, 2026 at 10:36 AM
#1
One of the best rootkits currently, hides very well for strong persistence.

Quote:Singularity is a sophisticated rootkit that operates at the kernel level, providing:
  • Process Hiding: Make any process completely invisible to the system
  • File & Directory Hiding: Conceal files using pattern matching
  • Network Stealth: Hide TCP/UDP connections, ports, and conntrack entries
  • Privilege Escalation: Signal-based instant root access
  • Log Sanitization: Filter kernel logs and system journals in real-time
  • Self-Hiding: Remove itself from module lists and system monitoring
  • Remote Access: ICMP-triggered reverse shell with automatic hiding
  • Anti-Detection: Evade eBPF-based runtime security tools (Falco, Tracee), bypass Linux Kernel Runtime Guard (LKRG), and prevent io_uring bypass attempts
  • Audit Evasion: Drop audit messages for hidden processes at netlink level with statistics tracking and socket inode filtering
  • Memory Forensics Evasion: Filter /proc/kcore, /proc/kallsyms, /proc/vmallocinfo
  • Cgroup Filtering: Filter hidden PIDs from cgroup.procs
  • Syslog Evasion: Hook do_syslog to filter klogctl() kernel ring buffer access
  • Debugfs Evasion: Filter output of tools like debugfs that read raw block devices
  • Conntrack Filtering: Hide connections from /proc/net/nf_conntrack and netlink SOCK_DIAG/NETFILTER queries
  • SELinux Evasion: Automatic SELinux enforcing mode bypass on ICMP trigger
  • LKRG Bypass: Evade Linux Kernel Runtime Guard detection mechanisms
  • eBPF Security Bypass: Hide processes from eBPF-based runtime security tools (Falco, Tracee)

https://github.com/MatheuZSecurity/Singularity

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply
#2
(Jan 23, 2026, 10:36 AM)netexec Wrote: One of the best rootkits currently, hides very well for strong persistence.

Quote:Singularity is a sophisticated rootkit that operates at the kernel level, providing:
  • Process Hiding: Make any process completely invisible to the system
  • File & Directory Hiding: Conceal files using pattern matching
  • Network Stealth: Hide TCP/UDP connections, ports, and conntrack entries
  • Privilege Escalation: Signal-based instant root access
  • Log Sanitization: Filter kernel logs and system journals in real-time
  • Self-Hiding: Remove itself from module lists and system monitoring
  • Remote Access: ICMP-triggered reverse shell with automatic hiding
  • Anti-Detection: Evade eBPF-based runtime security tools (Falco, Tracee), bypass Linux Kernel Runtime Guard (LKRG), and prevent io_uring bypass attempts
  • Audit Evasion: Drop audit messages for hidden processes at netlink level with statistics tracking and socket inode filtering
  • Memory Forensics Evasion: Filter /proc/kcore, /proc/kallsyms, /proc/vmallocinfo
  • Cgroup Filtering: Filter hidden PIDs from cgroup.procs
  • Syslog Evasion: Hook do_syslog to filter klogctl() kernel ring buffer access
  • Debugfs Evasion: Filter output of tools like debugfs that read raw block devices
  • Conntrack Filtering: Hide connections from /proc/net/nf_conntrack and netlink SOCK_DIAG/NETFILTER queries
  • SELinux Evasion: Automatic SELinux enforcing mode bypass on ICMP trigger
  • LKRG Bypass: Evade Linux Kernel Runtime Guard detection mechanisms
  • eBPF Security Bypass: Hide processes from eBPF-based runtime security tools (Falco, Tracee)

https://github.com/MatheuZSecurity/Singularity
Thanks

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Python Chrome Data Stealer (url, username/email, password, etc) Discord Webhook mooning 140 9,302 Yesterday, 05:37 PM
Last Post: gergergergerg5825g651eg
  Xordium stealer for Pulsar v2.4.5 nullvex 23 817 Yesterday, 02:48 PM
Last Post: kochamapi4api
  Bypass AV and EDR - Halos Gate from Sektor7 0x01 124 11,022 Apr 25, 2026, 11:13 AM
Last Post: Ususuussss
  Malware On Steroids Carpenter12 0 77 Feb 10, 2026, 07:06 PM
Last Post: Carpenter12
  Malware Extension Spoofer Psych1c 19 611 Feb 10, 2026, 08:02 AM
Last Post: ucy

Forum Jump:


 Users browsing this forum: 1 Guest(s)