RingReaper is a Linux-focused post-exploitation command-and-control agent developed by MatheuZSecurity. It uses the Linux io_uring asynchronous I/O interface to conduct operations with reduced conventional syscall telemetry, potentially weakening visibility for security products that rely heavily on syscall hooks, audit events, or eBPF-based monitoring. It is not inherently invisible; its activity can still be detected through io_uring-aware telemetry and behavioral correlation.
The agent supports interactive command execution, enumeration of users, sessions, processes, network connections, and privilege-escalation opportunities such as SUID binaries. It can transfer files to and from compromised hosts and establish a connection back to an operator-controlled server. RingReaper also includes a capability intended to disrupt eBPF-based defensive tooling by removing pinned eBPF objects and terminating processes interacting with eBPF maps, potentially impairing visibility provided by products using eBPF instrumentation. RingReaper has been characterized as an experimental post-exploitation and defense-evasion tool; no threat-actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux post-exploitation agent/backdoor that abuses io_uring to reduce traditional syscall-based EDR visibility. The content describes capabilities including reconnaissance, file transfer, C2 communications, command execution, session management, privilege-escalation discovery, and disruption of eBPF-based monitoring via its killbpf function.
A Linux rootkit or rootkit-like tool that abuses io_uring for stealthy post-compromise file, process, and user enumeration operations while reducing observable syscall activity.
Rootkit tool that uses io_uring for stealthier post-compromise file, process-enumeration, and I/O operations while reducing conventional syscall telemetry visibility.
Recently documented (2025) Linux rootkit cited as part of the modern generation of rootkits leveraging newer kernel features (e.g., eBPF/io_uring-era techniques) for stealth and evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.