Technique.View on attack.mitre.org
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.
Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems.
Rootkits that reside or modify boot sectors are known as Bootkits and specifically target the boot process of the operating system.
Rules on DetectionCode tagged with T1014.
| Rule | Level | Log source |
|---|---|---|
| Triple Cross eBPF Rootkit Install Commands | high | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Auditd Kernel Module Enumeration | Anomaly | NULL | Linux Auditd Syscall |
| Linux Kernel Module Enumeration | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Linux Medusa Rootkit | TTP | NULL | Sysmon for Linux EventID 11 |
| Windows Driver Load Non-Standard Path | TTP | NULL | Windows Event Log System 7045 |
| Windows Drivers Loaded by Signature | Hunting | NULL | Sysmon EventID 6 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax. |
| GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| GroupTeamTNT | TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| GroupWinnti Group | Winnti Group used a rootkit to modify typical server functionality. |
| Used by | Procedure example |
|---|---|
| MalwareCarberp | Carberp has used user mode rootkit techniques to remain hidden on the system. |
| MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a rootkit on a system. |
| MalwareCOATHANGER | COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices. |
| MalwareDrovorub | Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view. |
| MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| MalwareHiddenWasp | HiddenWasp uses a rootkit to hook and implement functions on the system. |
| MalwareHIDEDRV | HIDEDRV is a rootkit that hides certain operating system artifacts. |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
| CampaignRedPenguin | During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.