T1574.006Dynamic Linker Hijacking
T1574.006 — Dynamic Linker Hijacking is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 7 detection use cases covering it and 2 threat-intel articles citing it.
Defense EvasionExecution
7Use cases
2Articles
0Sub-techniques
2Tactics
↑ Parent technique: T1574 · Hijack Execution Flow
Use cases covering this technique (7)
GitHub Workflow File Creation or Modification Linux Auditd Preload Hijack Library Calls Linux Auditd Preload Hijack Via Preload File Linux Preload Hijack Library Calls Shai-Hulud Workflow File Creation or Modification [LLM] perfctl rootkit — /etc/ld.so.preload write or LD_PRELOAD on root daemon [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger)Articles citing this technique (2)
crit The XZ backdoor CVE-2024-3094 art-1266