Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org
Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.
Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges. On Linux, adversaries may set LD_PRELOAD to point to malicious libraries that match the name of legitimate libraries which are requested by a victim program, causing the operating system to load the adversary's malicious code upon execution of the victim program. For example, adversaries have used `LD_PRELOAD` to inject a malicious library into every descendant process of the `sshd` daemon, resulting in execution under a legitimate process. When the executing sub-process calls the `execve` function, for example, the malicious library’s `execve` function is executed rather than the system function `execve` contained in the system library on disk. This allows adversaries to Hide Artifacts from detection, as hooking system functions such as `execve` and `readdir` enables malware to scrub its own artifacts from the results of commands such as `ls`, `ldd`, `iptables`, and `dmesg`.
Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges.
Rules on DetectionCode tagged with T1574.006.
| Rule | Level | Log source |
|---|---|---|
| Code Injection by ld.so Preload | high | linux / NULL |
| Modification of ld.so.preload | high | linux / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| GitHub Workflow File Creation or Modification | Hunting | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
| Linux Auditd Preload Hijack Library Calls | TTP | NULL | Linux Auditd Execve |
| Linux Auditd Preload Hijack Via Preload File | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux Preload Hijack Library Calls | TTP | NULL | Sysmon for Linux EventID 1 |
| Shai-Hulud Workflow File Creation or Modification | TTP | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 has configured payloads to load via LD_PRELOAD. |
| GroupAquatic Panda | Aquatic Panda modified the |
| GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| Used by | Procedure example |
|---|---|
| MalwareCOATHANGER | COATHANGER copies the malicious file |
| MalwareEbury | When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`. |
| MalwareHiddenWasp | HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable. |
| MalwareHildegard | Hildegard has modified /etc/ld.so.preload to intercept shared library import functions. |
| MalwareMEDUSA | MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library. |
| MalwareSPAWNCHIMERA | SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection. |
| MalwareXCSSET | XCSSET adds malicious file paths to the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.