Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Systemd utilizes unit configuration files with the `.service` file extension to encode information about a service's process. By default, system level unit files are stored in the `/systemd/system` directory of the root owned directories (`/`). User level unit files are stored in the `/systemd/user` directories of the user owned directories (`$HOME`).
Inside the `.service` unit files, the following directives are used to execute commands:
* `ExecStart`, `ExecStartPre`, and `ExecStartPost` directives execute when a service is started manually by `systemctl` or on system start if the service is set to automatically start.
* `ExecReload` directive executes when a service restarts.
* `ExecStop`, `ExecStopPre`, and `ExecStopPost` directives execute when a service is stopped.
Adversaries have created new service files, altered the commands a `.service` file’s directive executes, and modified the user directive a `.service` file executes as, which could result in privilege escalation. Adversaries may also place symbolic links in these directories, enabling systemd to find these payloads regardless of where they reside on the filesystem.
The `.service` file’s User directive can be used to run service as a specific user, which could result in privilege escalation based on specific user/group permissions.
Systemd services can be created via systemd generators, which support the dynamic generation of unit files. Systemd generators are small executables that run during boot or configuration reloads to dynamically create or modify systemd unit files by converting non-native configurations into services, symlinks, or drop-ins (i.e., Boot or Logon Initialization Scripts).
Rules on DetectionCode tagged with T1543.002.
| Rule | Level | Log source |
|---|---|---|
| Systemd Service Creation | medium | linux / NULL |
| Service Reload or Start - Linux | low | linux / NULL |
| Used by | Procedure example |
|---|---|
| GroupRocke | Rocke has installed a systemd service script to maintain persistence. |
| GroupScattered Spider | Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/ |
| GroupTeamPCP | TeamPCP has used the systemd user service for malware persistence in targeted environments. |
| GroupTeamTNT | TeamTNT has established persistence through the creation of a cryptocurrency mining system service using |
| Used by | Procedure example |
|---|---|
| MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root. |
| MalwareFysbis | Fysbis has established persistence using a systemd service. |
| MalwareGomir | Gomir creates a systemd service named `syslogd` for persistence. |
| MalwareHildegard | Hildegard has started a monero service. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence. |
| ToolPupy | Pupy can be used to establish persistence using a systemd service. |
| MalwareRIFLESPINE | RIFLESPINE can create a systemd service file for execution. |
| MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder. |
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.