Symbiote is a Linux user-space rootkit and backdoor implemented as a malicious shared object. It uses dynamic-linker hijacking through LD_PRELOAD to load into running dynamically linked processes, where it hooks libc, PAM, and libpcap-related functions. This parasitic execution model enables it to conceal files, processes, network connections, and malicious activity from common user-space utilities and packet-capture tools. Symbiote filters network information exposed through procfs and can apply Berkeley Packet Filter logic to suppress selected traffic from captures.
Symbiote harvests credentials by intercepting PAM authentication data and terminal input from SSH and SCP processes. It encrypts collected data, stages it locally, and exfiltrates it through DNS requests. The malware also provides remote-access and authentication-bypass functionality, including a backdoor mechanism for privileged command execution. Symbiote was first publicly identified in 2021 in activity linked to attacks against financial-sector organizations in Latin America. Its initial infection vector is not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware hooks the following functions: fopen, fopen64, pam_authenticate, pam_set_item, read, readdir, readdir64, and recvmsg.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
Rootkits are a type of malware used by threat actors to gain complete control over a compromised resource and hide malicious activity.
Stripping binaries and appending a single null byte significantly degraded static detections; limited XOR string/configuration encoding and lightweight packing were also used.
The "magic packet" concept (TCP SYN with a window of 54321) is a form of traffic signaling to activate the passive C2.
The malware hides processes and files that are used during the activity by implementing two functions called hidden_proc and hidden_file. It can also hide network connections based on a list of ports
When /proc/net/tcp is passed into the malicious library’s open() function, it parses the file contents... the malware will not write the specific entry containing the remote IP address or local port... Finally, the malicious library’s open() function returns a file descriptor for the modified file, concealing the manipulation from the victim.
Symbiote uses BPF to hide malicious network traffic on infected systems... Symbiote first adds its bytecode so that it can filter the network traffic it wants to hide.
The malware hooks the following functions: fopen, fopen64, pam_authenticate, pam_set_item, read, readdir, readdir64, and recvmsg.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
This unconventional Linux malware abuses Berkeley Packet Filter (BPF) functionality to inspect network traffic directly inside the kernel, and passively listens for specially crafted network packets
Symbiote ... harvest[s] credentials by hooking libc's read function and checking whether the process that is calling it is ssh or scp. OrBit hooks functions in libc, libpcap, and PAM to harvest credentials.
If an SSH or SCP process is calling the libc read function, then hook_read is set to keylogger... The malware constructs a string with the following structure “<getaddrlist result>|<log_cmd_line result>|pw_5673”
The malware’s purpose is to steal credentials from the SSH and SCP processes by hooking the libc read function. | The process expects that the item_type value is equal to 0x6 ( PAM_AUTHTOK ), which is the authentication token (usually it’s a password)
In the function named getaddrlist, the ELF binary extracts a linked list of structures containing the network interfaces of the local machine using the getifaddrs method... The interfaces IP addresses are concatenated together
The malware calls the pam_get_item method in order to obtain the following information: ... PAM_USER – the username.
This unconventional Linux malware abuses Berkeley Packet Filter (BPF) functionality to inspect network traffic directly inside the kernel, and passively listens for specially crafted network packets
Symbiote ... harvest[s] credentials by hooking libc's read function and checking whether the process that is calling it is ssh or scp. OrBit hooks functions in libc, libpcap, and PAM to harvest credentials.
Thanks to it loading first, it can hijack imports from other library files uploaded for the application. Symbiote uses this to hide its presence on the machine by connecting the libc and libpcap functions.
the early BPFdoor installed a Berkeley Packet Filter inside the Linux kernel that inspected incoming network traffic. When a specially crafted “magic packet” containing a predefined byte sequence arrived at the correct port, the backdoor would activate and spawn a shell. Because the system never actually opened a port, tools such as netstat, ss, or nmap saw nothing unusual.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The article title and summary describe SPECTRE with Linux rootkit capabilities; Symbiote appears only in the tag list/sidebar content.
A Linux rootkit included in the dataset used to evaluate static detection reliability under stripping and trivial modification.
Linux rootkit included in static-detection testing; its detection rate fell materially after binary stripping and a trivial null-byte modification.
An eBPF-related malware family cited as an example of malware abusing kernel-level packet filtering for stealth and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.