Rootkit

T1014

Technique.View on attack.mitre.org

About this technique

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.

Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems.

Rootkits that reside or modify boot sectors are known as Bootkits and specifically target the boot process of the operating system.

Detection rules6

Rules on DetectionCode tagged with T1014.

Sigma1

RuleLevelLog source
Triple Cross eBPF Rootkit Install Commandshighlinux / process_creation

Splunk5

RuleTypeRiskData source
Linux Auditd Kernel Module EnumerationAnomalyNULLLinux Auditd Syscall
Linux Kernel Module EnumerationAnomalyNULLSysmon for Linux EventID 1
Linux Medusa RootkitTTPNULLSysmon for Linux EventID 11
Windows Driver Load Non-Standard PathTTPNULLWindows Event Log System 7045
Windows Drivers Loaded by SignatureHuntingNULLSysmon EventID 6

Groups6

Software24

Campaigns2

Procedure examples32

Groups6

Used byProcedure example
GroupAPT28

APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax.

GroupAPT41

APT41 deployed rootkits on Linux systems.

GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

GroupTeamTNT

TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine.

GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs.

GroupWinnti Group

Winnti Group used a rootkit to modify typical server functionality.

Software24

Used byProcedure example
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a rootkit on a system.

MalwareCOATHANGER

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

MalwareDrovorub

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

MalwareHiddenWasp

HiddenWasp uses a rootkit to hook and implement functions on the system.

MalwareHIDEDRV

HIDEDRV is a rootkit that hides certain operating system artifacts.

View all 24 software examples

Campaigns2

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

CampaignRedPenguin

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

References4

  1. BlackHat Mac OSX Rootkit Open source
    Pan, M., Tsai, S. (2014). You can’t see me: A Mac OS X Rootkit uses the tricks you haven't known yet. Retrieved December 21, 2017.
  2. CrowdStrike Linux Rootkit Open source
    Kurtz, G. (2012, November 19). HTTP iframe Injecting Linux Rootkit. Retrieved December 21, 2017.
  3. Symantec Windows Rootkits Open source
    Symantec. (n.d.). Windows Rootkit Overview. Retrieved December 21, 2017.
  4. Wikipedia Rootkit Open source
    Wikipedia. (2016, June 1). Rootkit. Retrieved June 2, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.