Technique.View on attack.mitre.org
Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.
Adversaries may establish persistence though modifications to host software binaries. For example, an adversary may replace or otherwise infect a legitimate application binary (or support files) with a backdoor. Since these binaries may be routinely executed by applications or the user, the adversary can leverage this for persistent access to the host. An adversary may also modify a software binary such as an SSH client in order to persistently collect credentials during logins (i.e., Modify Authentication Process).
An adversary may also modify an existing binary by patching in malicious functionality (e.g., IAT Hooking/Entry point patching) prior to the binary’s legitimate execution. For example, an adversary may modify the entry point of a binary to point to malicious code patched in by the adversary before resuming normal execution flow.
After modifying a binary, an adversary may attempt to impair defenses by preventing it from updating (e.g., via the `yum-versionlock` command or `versionlock.list` file in Linux systems that use the yum package manager).
Rules on DetectionCode tagged with T1554.
| Rule | Level | Log source |
|---|---|---|
| DNS HybridConnectionManager Service Bus | high | windows / dns_query |
| HybridConnectionManager Service Installation | high | windows / NULL |
| HybridConnectionManager Service Running | high | windows / NULL |
| Linux Setgid Capability Set on a Binary via Setcap Utility | low | linux / process_creation |
| Linux Setuid Capability Set on a Binary via Setcap Utility | low | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Circle CI Disable Security Job | Anomaly | NULL | CircleCI |
| Circle CI Disable Security Step | Anomaly | NULL | CircleCI |
| GitHub Workflow File Creation or Modification | Hunting | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
| Shai-Hulud Workflow File Creation or Modification | TTP | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAPT5 | APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence. |
| GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| Used by | Procedure example |
|---|---|
| MalwareBFG Agonizer | BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| MalwareBOLDMOVE | BOLDMOVE contains a watchdog-like feature that monitors a particular file for modification. If modification is detected, the legitimate file is backed up and replaced with a trojanized file to allow for persistence through likely system upgrades. |
| MalwareBonadan | Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| MalwareFRAMESTING | FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.` |
| MalwareGlassWorm | GlassWorm can modify hardware wallet applications. |
| MalwareIndustroyer | Industroyer has used a Trojanized version of the Windows Notepad application for an additional backdoor persistence mechanism. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer. |
| CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| CampaignRedPenguin | During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.