216.73.217.22

FlipSwitch: a Novel Syscall Hooking Technique

· Published 30/09/2025 13:02 · Modified 30/09/2025 20:12

Export JSON

Essential information

Published
30/09/2025 13:02
Modified
30/09/2025 20:12
Tags
2025-09-30 flipswitch kernel security linux kernel rootkit syscall hooking x86-64 yara
Related entities
1 observables, 4 techniques (mitre)

Description

introduces a new technique for 6.9+, bypassing traditional methods rendered obsolete by changes in the syscall dispatch mechanism. The technique locates the original syscall function, scans the x64_sys_call function's machine code for a specific call instruction, and modifies its offset to redirect to a malicious function. This precise method leaves minimal traces and can be fully reverted. demonstrates the ongoing evolution of attack techniques in response to kernel hardening efforts, highlighting the cat-and-mouse game between attackers and defenders in cybersecurity.

External references