Python Startup Hooks

T1546.018

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules. These files are automatically processed during the initialization of the Python interpreter, allowing for the execution of arbitrary code whenever Python is invoked.

Path configuration files are designed to extend Python’s module search paths through the use of import statements. If a `.pth` file is placed in Python's `site-packages` or `dist-packages` directories, any lines beginning with `import` will be executed automatically on Python invocation. Similarly, if `sitecustomize.py` or `usercustomize.py` is present in the Python path, these files will be imported during interpreter startup, and any code they contain will be executed.

Adversaries may abuse these mechanisms to establish persistence on systems where Python is widely used (e.g., for automation or scripting in production environments).

Detection rules0

Rules on DetectionCode tagged with T1546.018.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup.

References3

  1. DFIR Python Persistence 2025 Open source
    Stephan Berger. (2025, January 14). Analysis of Python's .pth files as a persistence mechanism. Retrieved May 22, 2025.
  2. Python Site Configuration Hook Open source
    Python. (n.d.). site — Site-specific configuration hook. Retrieved May 22, 2025.
  3. Volexity GlobalProtect CVE 2024 Open source
    Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved May 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.