Kernel Modules and Extensions

T1547.006

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces of code that can be loaded and unloaded into the kernel upon demand. They extend the functionality of the kernel without the need to reboot the system. For example, one type of module is the device driver, which allows the kernel to access hardware connected to the system.

When used maliciously, LKMs can be a type of kernel-mode Rootkit that run with the highest operating system privilege (Ring 0). Common features of LKM based rootkits include: hiding itself, selective hiding of files, processes and network activity, as well as log tampering, providing authenticated backdoors, and enabling root access to non-privileged users.

Kernel extensions, also called kext, are used in macOS to load functionality onto a system similar to LKMs for Linux. Since the kernel is responsible for enforcing security and the kernel extensions run as apart of the kernel, kexts are not governed by macOS security policies. Kexts are loaded and unloaded through kextload and kextunload commands. Kexts need to be signed with a developer ID that is granted privileges by Apple allowing it to sign Kernel extensions. Developers without these privileges may still sign kexts but they will not load unless SIP is disabled. If SIP is enabled, the kext signature is verified before being added to the AuxKC.

Since macOS Catalina 10.15, kernel extensions have been deprecated in favor of System Extensions. However, kexts are still allowed as "Legacy System Extensions" since there is no System Extension for Kernel Programming Interfaces.

Adversaries can use LKMs and kexts to conduct Persistence and/or Privilege Escalation on a system. Examples have been found in the wild, and there are some relevant open source projects as well.

Detection rules10

Rules on DetectionCode tagged with T1547.006.

Sigma1

RuleLevelLog source
Loading of Kernel Module via Insmodhighlinux / NULL

Splunk9

RuleTypeRiskData source
Linux Auditd Insert Kernel Module Using Insmod UtilityAnomalyNULLLinux Auditd Syscall
Linux Auditd Install Kernel Module Using Modprobe UtilityAnomalyNULLLinux Auditd Syscall
Linux Auditd Kernel Module Using Rmmod UtilityTTPNULLLinux Auditd Syscall
Linux Auditd Unload Module Via ModprobeTTPNULLLinux Auditd Execve
Linux File Created In Kernel Driver DirectoryAnomalyNULLSysmon for Linux EventID 11
Linux Insert Kernel Module Using Insmod UtilityAnomalyNULLSysmon for Linux EventID 1
Linux Install Kernel Module Using Modprobe UtilityAnomalyNULLSysmon for Linux EventID 1
Windows Snake Malware Kernel Driver ComadminTTPNULLSysmon EventID 11
Windows Snake Malware Service CreateTTPNULLWindows Event Log System 7045

Groups0

None recorded.

Software3

Campaigns1

Procedure examples4

Software3

Used byProcedure example
MalwareDrovorub

Drovorub can use kernel modules to establish persistence.

MalwareREPTILE

The REPTILE rootkit is implemented as a loadable kernel module (LKM).

MalwareSkidmap

Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.

Campaigns1

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence.

References13

  1. Apple Kernel Extension Deprecation Open source
    Apple. (n.d.). Deprecated Kernel Extensions and System Extension Alternatives. Retrieved November 4, 2020.
  2. CrowdStrike Linux Rootkit Open source
    Kurtz, G. (2012, November 19). HTTP iframe Injecting Linux Rootkit. Retrieved December 21, 2017.
  3. GitHub Diamorphine Open source
    Mello, V. (2018, March 8). Diamorphine - LMK rootkit for Linux Kernels 2.6.x/3.x/4.x (x86 and x86_64). Retrieved April 9, 2018.
  4. GitHub Reptile Open source
    Augusto, I. (2018, March 8). Reptile - LMK Linux rootkit. Retrieved April 9, 2018.
  5. Linux Kernel Module Programming Guide Open source
    Pomerantz, O., Salzman, P. (2003, April 4). Modules vs Programs. Retrieved November 17, 2024.
  6. Linux Kernel Programming Open source
    Pomerantz, O., Salzman, P.. (2003, April 4). The Linux Kernel Module Programming Guide. Retrieved April 6, 2018.
  7. RSAC 2015 San Francisco Patrick Wardle Open source
    Wardle, P. (2015, April). Malware Persistence on OS X Yosemite. Retrieved April 6, 2018.
  8. Securelist Ventir Open source
    Mikhail, K. (2014, October 16). The Ventir Trojan: assemble your MacOS spy. Retrieved April 6, 2018.
  9. Synack Secure Kernel Extension Broken Open source
    Wardle, P. (2017, September 8). High Sierra’s ‘Secure Kernel Extension Loading’ is Broken. Retrieved November 17, 2024.
  10. System and kernel extensions in macOS Open source
    Apple. (n.d.). System and kernel extensions in macOS. Retrieved March 31, 2022.
  11. Trend Micro Skidmap Open source
    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.
  12. Volatility Phalanx2 Open source
    Case, A. (2012, October 10). Phalanx 2 Revealed: Using Volatility to Analyze an Advanced Linux Rootkit. Retrieved April 9, 2018.
  13. iDefense Rootkit Overview Open source
    Chuvakin, A. (2003, February). An Overview of Rootkits. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.