Executive Summary
DirtyFrag (associated with RansomHub) is a weaponized exploitation toolkit targeting Linux systems, specifically identified on Ubuntu 22. It leverages a kernel vulnerability (CVE-2026-0526) related to page cache fragmentation and splice operations to achieve Local Privilege Escalation (LPE). The malware is highly engineered, featuring dual exploitation paths and automated post-exploitation tasks.
The attack chain involves creating isolated user and network namespaces to gain CAP_NET_RAW, followed by either a 'splice' abuse path or a complex RxRPC/AF_ALG cryptographic abuse path. A key innovation is its ability to perform 'stealth persistence' by patching the kernel page cache of sensitive files like /etc/passwd or /usr/bin/su without modifying the physical disk, rendering traditional file integrity monitoring ineffective.
This threat is of critical concern due to its AVX-512 accelerated cryptanalysis engine and high-performance kernel heap grooming techniques. It is designed for immediate impact, automatically exfiltrating shadow hashes and spawning interactive root shells once escalation is achieved.
