timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.11k stars 90 forks source link

[Intel]: https://sandflysecurity.com/blog/detecting-linux-binary-file-poisoning/ #719

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Defensive techniques

Parent threat

Execution, Persistence, Privilege Escalation, Defense Evasion

Finding

https://sandflysecurity.com/blog/detecting-linux-binary-file-poisoning/

Industry reference

attack:T1574:Hijack Execution Flow attack:T1204:User Execution attack:T1218:System Binary Proxy Execution attack:T1036.003:Rename System Utilities

Malware reference

No response

Actor reference

No response

Component

Linux, AIX, Solaris, HP-UX

Scenario

No response