Bedevil, also known as bdvl, is an open-source Linux userland rootkit that uses LD_PRELOAD-based shared-object injection to conceal activity and hijack system calls. Its installer can patch dynamic linker binaries in place, replacing the embedded reference to the conventional preload configuration location with a randomly generated, same-length alternative path. This causes dynamically linked processes to load the rootkit-controlled shared object while making the persistence mechanism less apparent to conventional checks. Bedevil can restore the original dynamic-linker configuration during removal. It has been associated with financially motivated activity attributed to Muddled Libra/Scattered Spider (also tracked as Octo Tempest), including compromises targeting VMware vCenter and ESXi infrastructure. The rootkit targets Linux systems; statically linked utilities are not subject to its LD_PRELOAD hooks and can assist with forensic inspection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
bedevil (bdvl), according to the GitHub page, is an LD_PRELOAD rootkit... The group Muddled Libra used bedevil to target VMware vCenter servers... In this blog post, we will conduct an in-depth analysis of the patching technique used by the bedevil rootkit.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
A unique technique Octo Tempest uses is compromising VMware ESXi infrastructure, installing the open-source Linux backdoor Bedevil, and then launching VMware Python scripts to run arbitrary commands against housed virtual machines.
Introduction bedevil (bdvl), according to the GitHub page, is an LD_PRELOAD rootkit... Most detection tools and scripts are typically capable of identifying a shared library path in the ld.so.preload file or detecting a non-empty LD_PRELOAD environment variable. | The rootkit comes with a nifty feature called Dynamic Linker Patching : Upon installation, the rootkit will patch the dynamic linker libraries... the code scans for various dynamic loaders on the compromised system... searches for occurrences of the string /etc/ld.so.preload. It then replaces this string with a new, randomly generated path.
Introduction bedevil (bdvl), according to the GitHub page, is an LD_PRELOAD rootkit. Therefore, this rootkit runs in userland.
Stripping binaries and appending a single null byte significantly degraded static detections; limited XOR string/configuration encoding and lightweight packing were also used.
Bummer. The rootkit is doing what it’s tasked to do. Protect the content of the malicious LD_PRELOAD file... cat and xxd returned “No such file or directory” because the rootkit had hooked various system calls.
Introduction bedevil (bdvl), according to the GitHub page, is an LD_PRELOAD rootkit... Most detection tools and scripts are typically capable of identifying a shared library path in the ld.so.preload file or detecting a non-empty LD_PRELOAD environment variable. | The rootkit comes with a nifty feature called Dynamic Linker Patching : Upon installation, the rootkit will patch the dynamic linker libraries... the code scans for various dynamic loaders on the compromised system... searches for occurrences of the string /etc/ld.so.preload. It then replaces this string with a new, randomly generated path.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux rootkit in the analyzed dataset; noted as stripped by default in the static detection comparison.
Linux rootkit included in static-detection testing; its binary is stripped by default.
A Linux userland LD_PRELOAD rootkit that patches dynamic linker libraries to replace references to /etc/ld.so.preload with a randomly generated preload path, improving stealth and helping hide the malicious shared library and hooked system calls.
Open-source Linux rootkit used against VMware vCenter servers during Scattered Spider intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.