Azazel is an open-source Linux userland rootkit, first documented in 2013, designed to conceal malicious activity and provide backdoor functionality. It uses shared-object injection and dynamic-linker hijacking to interpose libc functions, enabling the hiding of processes, files, directories, and network connections from standard administrative tools. Some versions include optional kernel-mode functionality. Azazel can establish persistence through manipulation of dynamic linker configuration and has also been associated with malicious PAM-based persistence techniques. The Winnti malware ecosystem has incorporated a modified Azazel-derived library to hide Linux backdoor processes and network activity. Azazel is relevant to Linux servers and enterprise infrastructure where attackers seek stealthy, persistent unauthorized access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
“Setting LD_PRELOAD=/path/to/rootkit.so allows the malicious shared object to override libc functions when the target binary executes.” | “By intercepting standard libc functions such as opendir, readdir, and fopen, these rootkits could manipulate the output of diagnostic tools like ps, ls, and netstat.”
“Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.”
Stripping binaries and appending a single null byte significantly degraded static detections; limited XOR string/configuration encoding and lightweight packing were also used.
The readdir function is modified to skip a file named "malicious_file," effectively hiding that file from the ls output. Azazel is used to hide processes, network connections, files, and directories.
“Setting LD_PRELOAD=/path/to/rootkit.so allows the malicious shared object to override libc functions when the target binary executes.” | “By intercepting standard libc functions such as opendir, readdir, and fopen, these rootkits could manipulate the output of diagnostic tools like ps, ls, and netstat.”
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux rootkit included in a VirusTotal-based static detection experiment showing that trivial binary modifications significantly reduce detection rates.
Linux rootkit included in static-detection testing; stripping or appending a null byte reduced antivirus detections.
Linux rootkit that uses shared-object injection and optional kernel-mode capabilities to hide processes, files, network ports, and enable backdoor functionality.
Linux rootkit leveraging shared-object injection (userland libc interposition) with optional kernel-mode capabilities; used for stealth (hiding processes/files/ports) and backdoor functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.