Dynamic Linker Hijacking

T1574.006

Sub-technique of T1574 Hijack Execution Flow.View on attack.mitre.org

About this technique

Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.

Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges. On Linux, adversaries may set LD_PRELOAD to point to malicious libraries that match the name of legitimate libraries which are requested by a victim program, causing the operating system to load the adversary's malicious code upon execution of the victim program. For example, adversaries have used `LD_PRELOAD` to inject a malicious library into every descendant process of the `sshd` daemon, resulting in execution under a legitimate process. When the executing sub-process calls the `execve` function, for example, the malicious library’s `execve` function is executed rather than the system function `execve` contained in the system library on disk. This allows adversaries to Hide Artifacts from detection, as hooking system functions such as `execve` and `readdir` enables malware to scrub its own artifacts from the results of commands such as `ls`, `ldd`, `iptables`, and `dmesg`.

Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges.

Detection rules7

Rules on DetectionCode tagged with T1574.006.

Sigma2

RuleLevelLog source
Code Injection by ld.so Preloadhighlinux / NULL
Modification of ld.so.preloadhighlinux / NULL

Splunk5

RuleTypeRiskData source
GitHub Workflow File Creation or ModificationHuntingNULLSysmon for Linux EventID 11, Sysmon EventID 11
Linux Auditd Preload Hijack Library CallsTTPNULLLinux Auditd Execve
Linux Auditd Preload Hijack Via Preload FileTTPNULLLinux Auditd Path, Linux Auditd Cwd
Linux Preload Hijack Library CallsTTPNULLSysmon for Linux EventID 1
Shai-Hulud Workflow File Creation or ModificationTTPNULLSysmon for Linux EventID 11, Sysmon EventID 11

Groups3

Software7

Campaigns0

None recorded.

Procedure examples10

Groups3

Used byProcedure example
GroupAPT41

APT41 has configured payloads to load via LD_PRELOAD.

GroupAquatic Panda

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.

GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

Software7

Used byProcedure example
MalwareCOATHANGER

COATHANGER copies the malicious file /data2/.bd.key/preload.so to /lib/preload.so, then launches a child process that executes the malicious file /data2/.bd.key/authd as /bin/authd with the arguments /lib/preload.so reboot newreboot 1. This injects the malicious preload.so file into the process with PID 1, and replaces its reboot function with the malicious newreboot function for persistence.

MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

MalwareHiddenWasp

HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable.

MalwareHildegard

Hildegard has modified /etc/ld.so.preload to intercept shared library import functions.

MalwareMEDUSA

MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library.

MalwareSPAWNCHIMERA

SPAWNCHIMERA has been compiled as a Position Independent Executable (PIE) to use a third-party library for injection.

MalwareXCSSET

XCSSET adds malicious file paths to the DYLD_FRAMEWORK_PATH and DYLD_LIBRARY_PATH environment variables to execute malicious code.

References10

  1. Apple Doco Archive Dynamic Libraries Open source
    Apple Inc.. (2012, July 23). Overview of Dynamic Libraries. Retrieved March 24, 2021.
  2. Baeldung LD_PRELOAD Open source
    baeldung. (2020, August 9). What Is the LD_PRELOAD Trick?. Retrieved March 24, 2021.
  3. ESET Ebury Oct 2017 Open source
    Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.
  4. Elastic Security Labs Pumakit 2024 Open source
    Remco Sprooten and Ruben Groenewoud. (2024, December 11). Declawing PUMAKIT. Retrieved March 24, 2025.
  5. Gabilondo DYLD_INSERT_LIBRARIES Catalina Bypass Open source
    Jon Gabilondo. (2019, September 22). How to Inject Code into Mach-O Apps. Part II.. Retrieved March 24, 2021.
  6. Intezer Symbiote 2022 Open source
    Joakim Kennedy and The BlackBerry Threat Research & Intelligence Team. (2022, June 9). Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat. Retrieved March 24, 2025.
  7. Man LD.SO Open source
    Kerrisk, M. (2020, June 13). Linux Programmer's Manual. Retrieved June 15, 2020.
  8. TLDP Shared Libraries Open source
    The Linux Documentation Project. (n.d.). Shared Libraries. Retrieved January 31, 2020.
  9. TheEvilBit DYLD_INSERT_LIBRARIES Open source
    Fitzl, C. (2019, July 9). DYLD_INSERT_LIBRARIES DYLIB injection in macOS / OSX. Retrieved March 26, 2020.
  10. Timac DYLD_INSERT_LIBRARIES Open source
    Timac. (2012, December 18). Simple code injection using DYLD_INSERT_LIBRARIES. Retrieved March 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.