Shared Modules

T1129

Technique.View on attack.mitre.org

About this technique

Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API).

Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective.

The Linux & macOS module loader can load and execute shared objects from arbitrary local paths. This functionality resides in `dlfcn.h` in functions such as `dlopen` and `dlsym`. Although macOS can execute `.so` files, common practice uses `.dylib` files.

The Windows module loader can be instructed to load DLLs from arbitrary local paths and arbitrary Universal Naming Convention (UNC) network paths. This functionality resides in `NTDLL.dll` and is part of the Windows Native API which is called from functions like `LoadLibrary` at run time.

Detection rules7

Rules on DetectionCode tagged with T1129.

Sigma1

RuleLevelLog source
Unsigned .node File Loadedmediumwindows / image_load

Splunk6

RuleTypeRiskData source
Linux Suspicious GCC Invocation Building Init Shared ObjectTTPNULLSysmon for Linux EventID 1
Windows Executable in Loaded ModulesTTPNULLSysmon EventID 7
Windows PowerShell Module File CreatedAnomalyNULLSysmon EventID 11
Windows PowerShell Script TabExpansion Direct CallAnomalyNULLPowershell Script Block Logging 4104
Windows Remote Image LoadAnomalyNULLSysmon EventID 7
Windows XLL File Creation Outside of Typical LocationAnomalyNULLSysmon EventID 11

Groups1

Software21

Campaigns0

None recorded.

Procedure examples22

Groups1

Used byProcedure example
GroupMustang Panda

Mustang Panda has leveraged `LoadLibrary` to load DLLs.

Software21

Used byProcedure example
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

MalwareAttor

Attor's dispatcher can execute additional plugins by loading the respective DLLs.

MalwareBLINDINGCAN

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

MalwareBOOSTWRITE

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

MalwareDarkWatchman

DarkWatchman can load DLLs.

MalwareDtrack

Dtrack contains a function that calls LoadLibrary and GetProcAddress.

MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

View all 21 software examples

References5

  1. Apple Dev Dynamic Libraries Open source
    Apple. (2012, July 23). Overview of Dynamic Libraries. Retrieved September 7, 2023.
  2. Linux Shared Libraries Open source
    Wheeler, D. (2003, April 11). Shared Libraries. Retrieved September 7, 2023.
  3. Microsoft DLL Open source
    Microsoft. (2023, April 28). What is a DLL. Retrieved September 7, 2023.
  4. RotaJakiro 2021 netlab360 analysis Open source
    Alex Turing, Hui Wang. (2021, April 28). RotaJakiro: A long live secret backdoor with 0 VT detection. Retrieved June 14, 2023.
  5. Unit42 OceanLotus 2017 Open source
    Erye Hernandez and Danny Tsechansky. (2017, June 22). The New and Improved macOS Backdoor from OceanLotus. Retrieved September 8, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.