Fileless ELF Execution via Kernel Keyring
20 days ago
- The technique uses the Linux kernel keyring to store an ELF payload in kernel memory without touching the filesystem.
- The payload is stored via the add_key syscall with type 'user', and retrieved via keyctl with KEYCTL_READ.
- After reading, the key is revoked (KEYCTL_REVOKE) so the payload only exists in an anonymous userspace mapping.
- The loader manually maps PT_LOAD segments from the ELF into memory, handling BSS and using MAP_FIXED_NOREPLACE.
- The entry point is jumped to directly (no execve), with proper x86-64 stack setup and register zeroing.
- The loader can optionally unlink its own binary (via /proc/self/exe), but this creates a '(deleted)' indicator that may trigger detection.
- The technique avoids file descriptors and inodes, leaving no traces in /proc/self/fd or on the filesystem (except the loader binary).
- Default per-user keyring quota is 20000 bytes; root can use /proc/sys/kernel/keys/root_maxbytes for larger payloads (up to 25 MB).
- The third argument to the loader becomes argv[0] and thread name via prctl(PR_SET_NAME), aiding stealth.