I tested the Singularity Linux kernel rootkit on VirusTotal using only basic obfuscation. At the time of submission, none of the engines detected the sample. This seems to highlight ongoing gaps in static detection for Linux kernel-level malware, especially custom or non-widespread threats.
VirusTotal report:
https://www.virustotal.com/gui/file/cd6ef163dd67482f8021ed21...
Source code:
https://github.com/MatheuZSecurity/Singularity