Break Process Trees

T1036.009

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the “parent-child" relationship for detection, breaking this relationship could result in the adversary’s behavior not being associated with previous process tree activity. On Unix-based systems breaking this process tree is common practice for administrators to execute software using scripts and programs.

On Linux systems, adversaries may execute a series of Native API calls to alter malware's process tree. For example, adversaries can execute their payload without any arguments, call the `fork()` API call twice, then have the parent process exit. This creates a grandchild process with no parent process that is immediately adopted by the `init` system process (PID 1), which successfully disconnects the execution of the adversary's payload from its previous process tree.

Another example is using the “daemon” syscall to detach from the current parent process and run in the background.

Detection rules2

Rules on DetectionCode tagged with T1036.009.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk2

RuleTypeRiskData source
Windows Svchost.exe Parent Process AnomalyAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688
Windows Unusual SysWOW64 Process Run System32 ExecutableAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
MalwareBPFDoor

After initial execution, BPFDoor forks itself and runs the fork with the `--init` flag, which allows it to execute secondary clean up operations. The parent process terminates leaving the forked process to be inherited by the legitimate process init.

MalwareShai-Hulud

Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.

References3

  1. 3OHA double-fork 2022 Open source
    Juan Tapiador. (2022, April 11). UNIX daemonization and the double fork. Retrieved September 29, 2023.
  2. Microsoft XorDdos Linux Stealth 2022 Open source
    Microsoft Threat Intelligence. (2022, May 19). Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices. Retrieved September 27, 2023.
  3. Sandfly BPFDoor 2022 Open source
    The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.