FlipSwitch is a proof-of-concept Linux x86-64 kernel rootkit technique for intercepting system calls on Linux kernel 6.9 and later. It addresses the switch-based syscall-dispatch implementation that made traditional sys_call_table pointer-overwrite hooks ineffective. FlipSwitch scans the compiled kernel syscall dispatcher for the call instruction associated with a selected syscall, then changes that instruction’s relative target to redirect execution to an attacker-controlled handler. The technique can resolve kernel symbols through kallsyms_lookup_name, including recovery of that resolver through a kprobe when it is not exported to loadable modules. It temporarily disables the x86 CR0 write-protect bit to modify read-only kernel code and restores the modification when the module unloads. As a syscall-hooking rootkit mechanism, it can support stealth and post-exploitation behavior by redirecting selected kernel syscall handling while leaving other dispatcher paths unchanged. Elastic Security published a YARA signature for identifying the proof-of-concept in Linux x86 files or memory.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
“FlipSwitch focuses on the compiled machine code of the kernel's new syscall dispatcher function, x64_sys_call... [and] overwrites [a] call-site... with a new offset pointing to a malicious, adversary-controlled function.” | “Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kernel syscall-dispatcher patching technique/rootkit approach for Linux 6.9+ that locates and rewrites call sites inside x64_sys_call (switch-based dispatcher) by temporarily disabling CR0 write-protect, enabling syscall interception despite sys_call_table no longer being in the execution path.
Linux rootkit technique that patches the kernel syscall dispatcher machine code to bypass a new switch-statement implementation.
Linux kernel rootkit proof-of-concept that hooks syscalls on x86-64 Linux kernel 6.9+ by patching the compiled machine code of the syscall dispatcher (x64_sys_call) rather than overwriting sys_call_table entries. It locates the target syscall function address (e.g., sys_kill) via sys_call_table/kallsyms_lookup_name (optionally obtained via kprobe), finds the corresponding call instruction in x64_sys_call, disables CR0 write-protect, and rewrites the call’s relative offset to redirect execution to attacker-controlled code; changes are reverted on module unload.
Linux x86-64 kernel rootkit proof of concept that hooks individual system calls after kernel 6.9 by locating and rewriting the relative offset of a call instruction in the x64_sys_call dispatcher. It temporarily disables CR0 write protection to patch kernel code and restores modifications on module unload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.