ATT&CKReferencesSandfly BPFDoor 2022

Sandfly BPFDoor 2022

The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBPFDoor

BPFDoor can require a password to activate the backdoor and uses RC4 encryption or static library encryption `libtomcrypt`.

T1036.009
Break Process Trees
MalwareBPFDoor

After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init.

T1036.011
Overwrite Process Arguments
MalwareBPFDoor

BPFDoor overwrites the `argv[0]` value used by the Linux `/proc` filesystem to determine the command line and command name to display for each process. BPFDoor selects a name from 10 hardcoded names that resemble Linux system daemons, such as; `/sbin/udevd -d`, `dbus-daemon --system`, `avahi-daemon: chroot helper`, `/sbin/auditd -n`, and `/usr/lib/systemd/systemd-journald`.

T1059.004
Unix Shell
MalwareBPFDoor

BPFDoor can create a reverse shell and supports vt100 emulator formatting.

T1070
Indicator Removal
MalwareBPFDoor

BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process.

T1070.004
File Deletion
MalwareBPFDoor

After initial setup, BPFDoor's original execution process deletes the dropped binary and exits.

T1070.006
Timestomp
MalwareBPFDoor

BPFDoor uses the `utimes()` function to change the executable's timestamp.

T1205.002
Socket Filters
MalwareBPFDoor

BPFDoor uses BPF bytecode to attach a filter to a network socket to view ICMP, UDP, or TCP packets coming through ports 22 (ssh), 80 (http), and 443 (https). When BPFDoor finds a packet containing its “magic” bytes, it parses out two fields and forks itself. The parent process continues to monitor filtered traffic while the child process executes the instructions from the parsed fields.

T1480
Execution Guardrails
MalwareBPFDoor

BPFDoor creates a zero byte PID file at `/var/run/haldrund.pid`. BPFDoor uses this file to determine if it is already running on a system to ensure only one instance is executing at a time.

T1686
Disable or Modify System Firewall
MalwareBPFDoor

BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port.

T1690
Prevent Command History Logging
MalwareBPFDoor

BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.