Systemd Timers

T1053.006

Sub-technique of T1053 Scheduled Task/Job.View on attack.mitre.org

About this technique

Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd timers are unit files with file extension .timer that control services. Timers can be set to run on a calendar event or after a time span relative to a starting point. They can be used as an alternative to Cron in Linux environments. Systemd timers may be activated remotely via the systemctl command line utility, which operates over SSH.

Each .timer file must have a corresponding .service file with the same name, e.g., example.timer and example.service. .service files are Systemd Service unit files that are managed by the systemd system and service manager. Privileged timers are written to /etc/systemd/system/ and /usr/lib/systemd/system while user level are written to ~/.config/systemd/user/.

An adversary may use systemd timers to execute malicious code at system startup or on a scheduled basis for persistence. Timers installed using privileged paths may be used to maintain root level persistence. Adversaries may also install user level timers to achieve user level persistence.

Detection rules4

Rules on DetectionCode tagged with T1053.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk4

RuleTypeRiskData source
Linux Auditd Service RestartedAnomalyNULLLinux Auditd Proctitle
Linux Service File Created In Systemd DirectoryAnomalyNULLSysmon for Linux EventID 11
Linux Service RestartedAnomalyNULLSysmon for Linux EventID 1
Linux Service Started Or EnabledAnomalyNULLSysmon for Linux EventID 1

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
MalwareCanisterWorm

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

MalwareMini Shai-Hulud

Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts.

References7

  1. Arch Linux Package Systemd Compromise BleepingComputer 10JUL2018 Open source
    Catalin Cimpanu. (2018, July 10). Malware Found in Arch Linux AUR Package Repository. Retrieved April 23, 2019.
  2. Falcon Sandbox smp: 28553b3a9d Open source
    Hybrid Analysis. (2018, July 11). HybridAnalsysis of sample 28553b3a9d2ad4361d33d29ac4bf771d008e0073cec01b5561c6348a608f8dd7. Retrieved September 8, 2023.
  3. Linux man-pages: systemd January 2014 Open source
    Linux man-pages. (2014, January). systemd(1) - Linux manual page. Retrieved April 23, 2019.
  4. Systemd Remote Control Open source
    Aaron Kili. (2018, January 16). How to Control Systemd Services on Remote Linux Server. Retrieved July 26, 2021.
  5. acroread package compromised Arch Linux Mail 8JUL2018 Open source
    Eli Schwartz. (2018, June 8). acroread package compromised. Retrieved April 23, 2019.
  6. archlinux Systemd Timers Aug 2020 Open source
    archlinux. (2020, August 11). systemd/Timers. Retrieved October 12, 2020.
  7. gist Arch package compromise 10JUL2018 Open source
    Catalin Cimpanu. (2018, July 10). ~x file downloaded in public Arch package compromise. Retrieved April 23, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.