Elastic Security Labs disclosed FlipSwitch, a proof-of-concept Linux x86-64 rootkit technique that regains syscall interception on Linux kernel 6.9 and later after traditional sys_call_table overwrites ceased to control syscall dispatch. FlipSwitch identifies the compiled x64_sys_call dispatcher’s call to a target syscall, such as sys_kill, and changes the call instruction’s relative offset to redirect execution to an attacker-controlled handler. It can obtain kernel symbol addresses through kallsyms_lookup_name, potentially recovered through a kprobe, and disables the CR0 write-protect bit temporarily to modify kernel code.
The technique underscores the evolution of modern Linux rootkits beyond static signatures and conventional syscall-table hooks. Elastic released a YARA rule to identify the FlipSwitch proof of concept in memory or on disk, while its broader detection guidance recommends runtime and behavioral monitoring for kernel modules, eBPF and io_uring abuse, shared-object injection, persistence, process masquerading, and log manipulation. Organizations should collect and correlate audit, kernel, file-integrity, process, and network telemetry, and enforce module signing, kernel hardening, least privilege, mandatory access controls, and timely patching.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
ARMO research described an io_uring-based defense-evasion technique that can reduce conventional syscall visibility on Linux kernel versions 5.1 and later.
Elastic assessed ten public Linux rootkits and found that stripping symbols or appending a null byte substantially reduced VirusTotal detections for most samples, demonstrating the fragility of static signature-based detection.
Elastic Security created the Linux_Rootkit_Flipswitch_821f3c9e YARA rule to identify the FlipSwitch proof of concept in memory or on disk.
Elastic Security documented FlipSwitch, a proof-of-concept Linux x86-64 rootkit technique that patches the relative offset of a CALL instruction in x64_sys_call to redirect a selected syscall, such as sys_kill, to an attacker-controlled handler.
Linux kernel 6.9 changed x86-64 syscall dispatch to switch statement-based handling in x64_sys_call, leaving sys_call_table available for compatibility but no longer used to dispatch system calls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceelastic.co
Open sourcevirusbulletin.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.