Skidmap

S0468

Malware.View on attack.mitre.org

About this malware

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1014
Rootkit

Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.

T1027.013
Encrypted/Encoded File

Skidmap has encrypted it's main payload using 3DES.

T1036.005
Match Legitimate Resource Name or Location

Skidmap has created a fake rm binary to replace the legitimate Linux binary.

T1053.003
Cron

Skidmap has installed itself via crontab.

T1057
Process Discovery

Skidmap has monitored critical processes to ensure resiliency.

T1059.004
Unix Shell

Skidmap has used pm.sh to download and install its main payload.

T1082
System Information Discovery

Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.

T1083
File and Directory Discovery

Skidmap has checked for the existence of specific files including /usr/sbin/setenforce and /etc/selinux/config. It also has the ability to monitor the cryptocurrency miner file and process.

T1098.004
SSH Authorized Keys

Skidmap has the ability to add the public key of its handlers to the authorized_keys file to maintain persistence on an infected host.

T1105
Ingress Tool Transfer

Skidmap has the ability to download files on an infected host.

T1140
Deobfuscate/Decode Files or Information

Skidmap has the ability to download, unpack, and decrypt tar.gz files .

T1496.001
Compute Hijacking

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

T1518.001
Security Software Discovery

Skidmap has the ability to check if /usr/sbin/setenforce exists. This file controls what mode SELinux is in.

T1547.006
Kernel Modules and Extensions

Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.

T1556.003
Pluggable Authentication Modules

Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Trend Micro Skidmap Open source
    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.