Diamorphine is an open-source Linux loadable-kernel-module rootkit. It uses system-call hooking, traditionally through modification of syscall-table handlers, to conceal processes, files, directories, and its own kernel-module presence. It can use a kprobe-based technique to resolve kernel symbols on systems where direct symbol access is restricted. Diamorphine also uses unusual kill signals as covert control triggers, including for privilege manipulation and toggling stealth functionality. The rootkit requires high privileges to load and is commonly compiled for the target kernel environment. It has been deployed by TeamTNT in cloud and container-focused cryptojacking operations to hide cryptocurrency-mining processes, including following compromise of exposed or misconfigured services. Its kernel-level execution provides defense evasion and persistence on Linux hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamTNT ... used the Diamorphine open-source LKM rootkit to hide cryptomining process.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The signal SIGSUPER = 64 obtains root privileges by committing new credentials with uids = 0.
“By overwriting a pointer in this table, an attacker can redirect a legitimate syscall, such as getdents64, kill, or read, to a malicious handler.” | “Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.” | “A recent update to Diamorphine used this technique. It places a kprobe to grab the pointer of kallsyms_lookup_name itself.”
Stripping binaries and appending a single null byte significantly degraded static detections; limited XOR string/configuration encoding and lightweight packing were also used.
This empowers a rootkit to filter the output of the ls command to hide malicious files or prevent a specific process from being terminated.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel rootkit discussed as using unusual kill signals and as detectable through kernel module loading telemetry such as finit_module/init_module syscall monitoring.
Kernel-module Linux rootkit whose loading can be detected through init_module/finit_module syscall telemetry; it can use unusual high-numbered kill signals as covert triggers.
Mentioned solely as an example of a modern rootkit associated with the kprobe trick for resolving kallsyms_lookup_name on newer Linux kernels.
Linux loadable-kernel-module rootkit that hooks system calls, disables CR0 write protection to alter kernel behavior, and can use kprobes to resolve hidden symbols.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.