Systemd Service

T1543.002

Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org

About this technique

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Systemd utilizes unit configuration files with the `.service` file extension to encode information about a service's process. By default, system level unit files are stored in the `/systemd/system` directory of the root owned directories (`/`). User level unit files are stored in the `/systemd/user` directories of the user owned directories (`$HOME`).

Inside the `.service` unit files, the following directives are used to execute commands:

* `ExecStart`, `ExecStartPre`, and `ExecStartPost` directives execute when a service is started manually by `systemctl` or on system start if the service is set to automatically start.
* `ExecReload` directive executes when a service restarts.
* `ExecStop`, `ExecStopPre`, and `ExecStopPost` directives execute when a service is stopped.

Adversaries have created new service files, altered the commands a `.service` file’s directive executes, and modified the user directive a `.service` file executes as, which could result in privilege escalation. Adversaries may also place symbolic links in these directories, enabling systemd to find these payloads regardless of where they reside on the filesystem.

The `.service` file’s User directive can be used to run service as a specific user, which could result in privilege escalation based on specific user/group permissions.

Systemd services can be created via systemd generators, which support the dynamic generation of unit files. Systemd generators are small executables that run during boot or configuration reloads to dynamically create or modify systemd unit files by converting non-native configurations into services, symlinks, or drop-ins (i.e., Boot or Logon Initialization Scripts).

Detection rules2

Rules on DetectionCode tagged with T1543.002.

Sigma2

RuleLevelLog source
Systemd Service Creationmediumlinux / NULL
Service Reload or Start - Linuxlowlinux / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software11

Campaigns1

Procedure examples16

Groups4

Used byProcedure example
GroupRocke

Rocke has installed a systemd service script to maintain persistence.

GroupScattered Spider

Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/
system/teleport.service` to establish persistence for the Teleport remote access tool.

GroupTeamPCP

TeamPCP has used the systemd user service for malware persistence in targeted environments.

GroupTeamTNT

TeamTNT has established persistence through the creation of a cryptocurrency mining system service using systemctl.

Software11

Used byProcedure example
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

MalwareFysbis

Fysbis has established persistence using a systemd service.

MalwareGomir

Gomir creates a systemd service named `syslogd` for persistence.

MalwareHildegard

Hildegard has started a monero service.

MalwareMini Shai-Hulud

Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence.

ToolPupy

Pupy can be used to establish persistence using a systemd service.

MalwareRIFLESPINE

RIFLESPINE can create a systemd service file for execution.

MalwareRotaJakiro

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

View all 11 software examples

Campaigns1

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins.

References8

  1. Anomali Rocke March 2019 Open source
    Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.
  2. Elastic Security Labs Linux Persistence 2024 Open source
    Ruben Groenewoud. (2024, August 20). Linux Detection Engineering - A primer on persistence mechanisms. Retrieved March 18, 2025.
  3. Linux man-pages: systemd January 2014 Open source
    Linux man-pages. (2014, January). systemd(1) - Linux manual page. Retrieved April 23, 2019.
  4. Pepe Berba Systemd 2022 Open source
    Pepe Berba. (2022, February 7). Hunting for Persistence in Linux (Part 5): Systemd Generators. Retrieved April 8, 2025.
  5. Rapid7 Service Persistence 22JUNE2016 Open source
    Rapid7. (2016, June 22). Service Persistence. Retrieved April 23, 2019.
  6. airwalk backdoor unix systems Open source
    airwalk. (2023, January 1). A guide to backdooring Unix systems. Retrieved May 31, 2023.
  7. freedesktop systemd.service Open source
    Free Desktop. (n.d.). systemd.service — Service unit configuration. Retrieved March 20, 2023.
  8. lambert systemd 2022 Open source
    Tony Lambert. (2022, November 13). ATT&CK T1501: Understanding systemd service persistence. Retrieved March 20, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.