Curing is a public proof-of-concept Linux rootkit developed by ARMO in April 2025 to demonstrate how malware can evade syscall-centric endpoint monitoring by abusing io_uring, the Linux asynchronous I/O interface. Written in Go and C, it performs malicious activity through io_uring operations rather than conventional per-operation system calls, creating a visibility gap for security products that rely primarily on syscall-layer telemetry or eBPF instrumentation attached only at that layer.
The rootkit was designed to show that file access, file modification, symbolic-link creation, and command-and-control communications can be carried out through io_uring while leaving little or no attack-relevant syscall trace visible to tools such as strace and some Linux EDR configurations. Reported behaviors include pulling commands from a remote command-and-control server, reading and writing local files, and conducting network communications through io_uring-backed operations. This makes it relevant as a defense-evasion case study for Linux environments running modern kernels that support io_uring.
Curing is not attributed to any threat actor and has not been confirmed as used in the wild. It is a defensive research demonstration intended to expose detection blind spots in Linux observability and endpoint security tooling. Testing associated with the proof of concept showed that some products and configurations could miss sensitive file reads, malicious payload staging, and suspicious outbound communications when those actions were mediated through io_uring, while approaches using kernel enforcement-path visibility such as LSM or KRSI-based monitoring were presented as more resilient. The project illustrates an emerging Linux stealth technique with potential for weaponization because the underlying mechanism is broadly available in contemporary Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux proof-of-concept rootkit that uses io_uring to read and write files, create symbolic links, and communicate with a remote C2 while avoiding syscall-based monitoring by Linux EDR tools.
PoC Linux rootkit leveraging io_uring to bypass system call-based threat detection/monitoring.
Proof-of-concept Linux rootkit that abuses io_uring to evade detection by security tools that rely on system-call monitoring.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.