Hasty Briefsbeta

Bilingual

Fileless ELF Execution via Kernel Keyring

20 days ago
  • The technique uses the Linux kernel keyring to store an ELF payload in kernel memory without touching the filesystem.
  • The payload is stored via the add_key syscall with type 'user', and retrieved via keyctl with KEYCTL_READ.
  • After reading, the key is revoked (KEYCTL_REVOKE) so the payload only exists in an anonymous userspace mapping.
  • The loader manually maps PT_LOAD segments from the ELF into memory, handling BSS and using MAP_FIXED_NOREPLACE.
  • The entry point is jumped to directly (no execve), with proper x86-64 stack setup and register zeroing.
  • The loader can optionally unlink its own binary (via /proc/self/exe), but this creates a '(deleted)' indicator that may trigger detection.
  • The technique avoids file descriptors and inodes, leaving no traces in /proc/self/fd or on the filesystem (except the loader binary).
  • Default per-user keyring quota is 20000 bytes; root can use /proc/sys/kernel/keys/root_maxbytes for larger payloads (up to 25 MB).
  • The third argument to the loader becomes argv[0] and thread name via prctl(PR_SET_NAME), aiding stealth.