Skip to content
Threat Feed
medium advisory

Detection of Suspicious Shared Object Creation on Linux

This brief addresses the detection of unauthorized shared object (.so) file creation in sensitive system directories, a technique commonly used by attackers for persistence and code injection on Linux systems.

Monitoring for the creation of shared object files is critical for identifying persistence mechanisms on Linux endpoints. Attackers often compile malicious code into dynamically linked libraries (.so files) and place them in system directories to achieve execution, inject functionality into legitimate processes, or bypass security controls at runtime. While legitimate system management tasks, such as software updates or application installations, frequently involve the creation of these files, malicious activity is often characterized by the use of previously unknown or uncommon processes performing these actions outside of standard package management workflows. By tracking file creation events in sensitive library paths, security teams can identify potentially unauthorized library loading or backdooring of applications that would otherwise evade standard process-based detection.

Impact

Successful exploitation allows for stealthy persistence, privilege escalation via code injection, and potential bypass of security monitoring. Compromised systems may experience reduced integrity and confidentiality as malicious libraries interact with system-level services and user applications. If left undetected, this allows attackers to maintain long-term access, execute unauthorized code within the context of trusted processes, and exfiltrate sensitive data.

Recommendation

Prioritize the investigation of file creation events in sensitive directories triggered by unknown processes.

  • Deploy the provided Sigma rule to detect the creation of shared object files in system-wide library paths.
  • Tune existing detection logic by creating allowlists for known-good administrative processes and package managers documented in the Sigma filter.
  • Utilize OSQuery to perform ad-hoc investigation of suspect shared objects, checking for file ownership, modification times, and associated process trees.
  • Investigate the parent process of any suspicious .so creation to determine the execution chain and evaluate if the binary originates from a trusted source.

Immediate actions

Deploy the Sigma rule to the SIEM

Detection Engineering 48h

Threat Hunt

Search for recently created .so files in sensitive paths not associated with known package managers

T1546.002 medium medium confidence hunt now

Data: File system audit logs

Mitigations

Implement strict file integrity monitoring (FIM) on /usr/lib and /lib directories

medium IT Operations

Persistence via file modification

Detection coverage 1

Detect Suspicious Shared Object Creation

medium

Detects the creation of shared object files in critical system directories by unknown processes, which may indicate persistence or unauthorized code injection.

sigma tactics: persistence techniques: T1546.002 sources: file_event, linux

Detection queries are available on the platform. Get full rules →