{"id":"T1574.006","name":"Dynamic Linker Hijacking","url":"https://attack.mitre.org/techniques/T1574/006","tactics":["stealth","execution"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0435","stix_id":"x-mitre-detection-strategy--da2107bd-4733-4d0b-a35c-33f7883e9ae9","name":"Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking","url":"https://attack.mitre.org/detectionstrategies/DET0435","analytics":[{"id":"AN1209","stix_id":"x-mitre-analytic--048adb6e-49a1-463e-bc0d-0a9a543cf0ce","name":"Analytic 1209","description":"Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0435#AN1209","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve with LD_PRELOAD or linker-related environment variables set","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"creation of .so files in non-standard directories (e.g., /tmp, /home/*)","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-path"},{"name":"linux:osquery","channel":"process environment variables containing LD_PRELOAD","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"WatchedEnvVars","description":"Environment variables like LD_PRELOAD, LD_LIBRARY_PATH. Defenders can tune based on development vs. production systems."},{"field":"MonitoredDirectories","description":"Non-standard library paths (e.g., /tmp, user home dirs). May be tuned to reduce false positives from benign development activity."},{"field":"CorrelationWindow","description":"Timeframe to correlate suspicious library creation with process execution that loads it."}],"live":true,"detection_strategies":["DET0435"],"techniques":["T1574.006"]},{"id":"AN1210","stix_id":"x-mitre-analytic--5907bfc2-a5d6-4ff1-bba8-8b94c9835ed6","name":"Analytic 1210","description":"Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history.","url":"https://attack.mitre.org/detectionstrategies/DET0435#AN1210","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of process with DYLD_INSERT_LIBRARIES set","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"create/modify dylib in monitored directories","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"loading of unexpected dylibs compared to historical baselines","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedEnvVars","description":"macOS linker variables like DYLD_INSERT_LIBRARIES. Tunable to development environments where use may be expected."},{"field":"BaselineDylibs","description":"Known dylibs typically loaded by apps. Deviations highlight potential hijacking."},{"field":"MonitoredDirectories","description":"Locations where dylibs are monitored for tampering (e.g., /Applications, /System/Library, /tmp)."}],"live":true,"detection_strategies":["DET0435"],"techniques":["T1574.006"]}],"live":true,"version":"1.0","techniques":["T1574.006"]}],"sigma_rules":[{"id":"4b3cb710-5e83-4715-8c45-8b2b5b3e5751","title":"Modification of ld.so.preload","author":"E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Identifies modification of ld.so.preload for shared object injection. This technique is used by attackers to load arbitrary code into processes.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1574.006/T1574.006.md","https://eqllib.readthedocs.io/en/latest/analytics/fd9b987a-1101-4ed3-bda6-a70300eaf57e.html"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.006"],"path":"rules/linux/auditd/path/lnx_auditd_ld_so_preload_mod.yml","techniques":["T1574.006"],"cves":[]},{"id":"7e3c4651-c347-40c4-b1d4-d48590fdf684","title":"Code Injection by ld.so Preload","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-05-05","modified":"2022-10-09","description":"Detects the ld.so preload persistence file. See `man ld.so` for more information.","references":["https://man7.org/linux/man-pages/man8/ld.so.8.html"],"logsource":{"product":"linux"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.006"],"path":"rules/linux/builtin/lnx_ldso_preload_injection.yml","techniques":["T1574.006"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}