libprocesshider
libprocesshider is a Linux userland rootkit/process-hiding tool used for defense evasion. The provided content states that TeamTNT used libprocesshider to modify /etc/ld.so.preload, consistent with its use to hide malicious processes such as cryptocurrency miners on compromised Linux, cloud, and containerized environments. The content also notes libprocesshider among tools used in Sandworm/APT44 activity tracked by CERT-UA during a 2024 campaign targeting Ukrainian critical infrastructure organizations in the energy, water, and heat sectors, including Linux hosts used for industrial process automation. High-confidence associations in the content therefore link libprocesshider to TeamTNT and to Sandworm/UAC-0133 operations. No specific standalone indicators of compromise for libprocesshider itself are provided beyond the modification of /etc/ld.so.preload.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Userland process-hiding tool (LD_PRELOAD-based) used to conceal malicious processes (e.g., miners) on Linux systems.
Linux userland process-hiding library (commonly via LD_PRELOAD) used to conceal malicious processes/artifacts.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.