timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.1k stars 91 forks source link

[Intel]: https://www.cadosecurity.com/kiss-a-dog-discovered-utilizing-a-20-year-old-process-hider/ #770

Open timb-machine opened 6 months ago

timb-machine commented 6 months ago

Area

Malware reports

Parent threat

Initial Access, Persistence, Defense Evasion, Impact

Finding

https://www.cadosecurity.com/kiss-a-dog-discovered-utilizing-a-20-year-old-process-hider/

Industry reference

uses:ProcessTreeSpoofing uses:TamperedPS uses:Python attack:T1140:Deobfuscate/Decode Files or Information attack:T1496:Resource Hijacking attack:T1547.006:Kernel Modules and Extensions attack:T1574.006:Dynamic Linker Hijacking

Malware reference

XHide XMRig Diamorphine libprocesshider

Actor reference

Kiss-a-Dog

Component

Linux

Scenario

Cloud hosted services