A sophisticated Linux rootkit designed to bypass the defenses of Elastic Security, a leading endpoint detection and response (EDR) platform, has been released on GitHub by researcher 0xMatheuZ. The rootkit uses advanced obfuscation techniques to evade YARA-based detection and behavioral tracking.
See also: Gunra ransomware attacks Windows and Linux

Although presented strictly for educational purposes, Singularity highlights the evolving challenges in kernel-level threat detection, potentially providing insights to both attackers and defenders in the cybersecurity arms race. Elastic Security, integrated with Elastic Defend, typically triggers over two dozen alerts during rootkit scans, including file quarantines and process terminations.
Singularity addresses this by splitting its code, randomizing identifiers, and loading payloads into memory, achieving complete evasion during testing. Key features include hiding processes from /proc, hiding files and directories with patterns like “singularity” or “matheuz,” hiding TCP connections on port 8081, and enabling privilege escalation via custom signals or environment variables. It also features an ICMP-based backdoor for reverse shells triggered by specific packet sequences, along with anti-analysis measures that block tracing and clean up logs.
At the heart of Singularity’s success is a multi-layered approach to avoiding static analysis. Traditional rootkits fail on predictable strings and symbols targeted by YARA rules, such as “kallsyms_lookup_name” combined with “license=GPL” or hooks like “hook_getdents”. The rootkit’s Python-based obfuscator breaks these up at compile time, splitting the strings, while the C compiler recompiles—e.g., turning MODULE_LICENSE(“GPL”) into MODULE_LICENSE(“G” “P” “L”). This ensures functionality while making the binary strings non-contiguous for scanners, as confirmed by tools like strings and objdump that do not show direct matches.
See also: PoC exploit released for Linux-PAM vulnerability

Symbol name randomization takes this further, replacing suspicious prefixes (“hook_”, “fake_”) with innocent, kernel-mimicking names like “sys_abjker_handler” or “kern_wopqls_helper”. A whitelist protects core kernel APIs, and regex patterns extract functions for consistent renaming, sorted by length to avoid partial replacements. The ftrace hook functions, another common element, receive similar treatment, renaming “fh_install_hook” to avoid rules that detect two or more such patterns. These techniques collectively dismantle the 57 function name signatures in Elastic’s generic rootkit rules.
In addition to static techniques, Singularity splits the compiled .ko into 64KB chunks XORed using a 16-byte random key, stored along with metadata for reassembly. A custom loader, statically compiled, reassembles these in memory via memfd_create, an anonymous file descriptor that avoids files on disk. It uses direct system calls (both 64-bit and legacy 32-bit via int $0x80 ) to call finit_module, bypassing the hooked libc functions. This memory-only loading resists detection on disk, with the chunks being able to be deleted after execution.
Behavior detection proves more difficult, especially for ICMP-triggered reverse shell. Elastic flags patterns like setsid with /dev/tcp/ on command lines or shell executions by kernel workers. Singularity addresses this by writing a staged bash script in /singularity , immediately hiding the PID of the kworker it spawns, and then running a clean /bin/bash /singularity. The script opens a TCP handle, spawns sh in the background, and uses kill -59 on precise PIDs for targeted hiding and escalation, bypassing command line examination without affecting legitimate processes.
See also: Vulnerability Exploited in Linux Kernel's ksmbd File System

Additional workarounds include compiling loaders to /tmp instead of the monitored /dev/shm and automating the hiding pipeline for reproducibility. In testing, Singularity loaded without detection, hid processes, and established connections without triggering alerts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
