[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOJ8k54GoQF4FH7VkYNo_uvkIWD_5U9uTRxvAgS1K4H4":3},{"article":4,"iocs":44,"watch_terms":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":33},"bbb8fe76-02b2-49a9-a225-95f8ed0b5302","Outflank published “Linux Process Injection via Seccomp User Notifications” 4 months ago.\n\nWhen t...","outflank-published-linux-process-injection-via-seccomp-user-notifications-4-mont-760fd7","Outflank published “Linux Process Injection via Seccomp User Notifications” 4 months ago.\n\nWhen the first sample hit VT 2 months ago, detection was still at 0\u002F64.\n\nSHA256:\nc8cdf46fcbaebba29df13ca40a3ab8d37cdac54e333b3957facf4ef6c88cef34\n\nTHOR detected it with: https:\u002F\u002Ft.co\u002FralUCpmTrd","Outflank disclosed a Linux process injection technique leveraging seccomp user notifications 4 months ago. A malware sample implementing this technique remained undetected by all 64 VirusTotal engines for 2 months after initial submission, highlighting evasion effectiveness. Detection was eventually achieved through THOR's rules.","Linux process injection malware via seccomp evades detection on VirusTotal.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2046662558422040830","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGczhPtXYAAmRhF.jpg","2026-04-21T18:49:13+00:00","2026-04-21T19:00:07.741527+00:00",7,[18,21,24,26],{"name":19,"type":20},"Outflank","vendor",{"name":22,"type":23},"seccomp","technology",{"name":25,"type":23},"VirusTotal",{"name":27,"type":28},"THOR","product","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":29,"icon":11,"name":31,"slug":32},"Malware","malware",[34,39],{"category":35},{"id":36,"icon":11,"name":37,"slug":38},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":40},{"id":41,"icon":11,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[45],{"type":46,"value":47,"context":48},"hash_sha256","c8cdf46fcbaebba29df13ca40a3ab8d37cdac54e333b3957facf4ef6c88cef34","Malware sample implementing Linux seccomp process injection technique",[19,27]]