Compromise Host Software Binary

T1554

Technique.View on attack.mitre.org

About this technique

Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.

Adversaries may establish persistence though modifications to host software binaries. For example, an adversary may replace or otherwise infect a legitimate application binary (or support files) with a backdoor. Since these binaries may be routinely executed by applications or the user, the adversary can leverage this for persistent access to the host. An adversary may also modify a software binary such as an SSH client in order to persistently collect credentials during logins (i.e., Modify Authentication Process).

An adversary may also modify an existing binary by patching in malicious functionality (e.g., IAT Hooking/Entry point patching) prior to the binary’s legitimate execution. For example, an adversary may modify the entry point of a binary to point to malicious code patched in by the adversary before resuming normal execution flow.

After modifying a binary, an adversary may attempt to impair defenses by preventing it from updating (e.g., via the `yum-versionlock` command or `versionlock.list` file in Linux systems that use the yum package manager).

Detection rules9

Rules on DetectionCode tagged with T1554.

Sigma5

Splunk4

RuleTypeRiskData source
Circle CI Disable Security JobAnomalyNULLCircleCI
Circle CI Disable Security StepAnomalyNULLCircleCI
GitHub Workflow File Creation or ModificationHuntingNULLSysmon for Linux EventID 11, Sysmon EventID 11
Shai-Hulud Workflow File Creation or ModificationTTPNULLSysmon for Linux EventID 11, Sysmon EventID 11

Groups2

Software19

Campaigns3

Procedure examples24

Groups2

Used byProcedure example
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

Software19

Used byProcedure example
MalwareBFG Agonizer

BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use.

MalwareBOLDMOVE

BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades.

MalwareBonadan

Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

MalwareBUSHWALK

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

MalwareFRAMESTING

FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.`

MalwareGlassWorm

GlassWorm can modify hardware wallet applications.

MalwareIndustroyer

Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism.

View all 19 software examples

Campaigns3

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer.

CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

CampaignRedPenguin

During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.

References3

  1. ESET FontOnLake Analysis 2021 Open source
    Vladislav Hrčka. (2021, January 1). FontOnLake. Retrieved September 27, 2023.
  2. Google Cloud Mandiant UNC3886 2024 Open source
    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.
  3. Unit42 Banking Trojans Hooking 2022 Open source
    Or Chechik. (2022, October 31). Banking Trojan Techniques: How Financially Motivated Malware Became Infrastructure. Retrieved September 27, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.