PANIX is a modular Linux persistence and post-exploitation framework developed by Ruben Groenewoud of Elastic Security for authorized security research, detection engineering, penetration testing, and CTF use. It automates deployment and removal of numerous user-level and privileged persistence mechanisms, including scheduled tasks, service and boot-start mechanisms, shell initialization changes, XDG autostart entries, SSH authorized-key backdoors, system-account manipulation, dynamic linker hijacking, kernel modules, web shells, package-manager hooks, Git hooks, udev rules, and system-binary hijacking. PANIX also supports mechanisms that can provide elevated or root-level access, including SUID or capability abuse, sudoers changes, PAM, Polkit, UID-zero accounts, bootloader and initramfs modifications, and container-based host escape persistence. Modules include paired setup and revert functionality and ATT&CK technique mappings, enabling repeatable adversary-emulation exercises and validation of Linux host detections across several major distributions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
At is a utility for scheduling one-time tasks to run at a specified time in the future on Linux systems.
Attackers can exploit [cron] jobs to run scripts or binaries that establish reverse connections or add reverse shell commands.
A timer unit specifies the schedule and is associated with a corresponding service unit that performs the task.
Reverse shells are utilized in many of the persistence techniques discussed in this article. | A bind shell listens for incoming connections on the compromised host. This allows the attacker to connect at will, gaining command execution on the target machine.
D-Bus abuse aligns closely with T1543: Create or Modify System Process, as well as T1574: Hijack Execution Flow for cases where .service files are modified.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
Attackers deploy custom containers designed to break out of isolation. These containers often include exploits, scripts for privilege escalation or persistence, such as reverse shells or C2 beacons, and malicious configurations enabling unauthorized access to host resources.
Dynamic MOTD scripts stored in /etc/update-motd.d/ execute shell commands every time a user logs in. | SysV init scripts in /etc/init.d/ are executed with root privileges and can be enabled through update-rc.d to run at boot.
The rc.local script contains commands executed at the end of system boot; systemd-rc-local-generator enables it when /etc/rc.local exists and is executable.
The following analytic detects potential persistence using a systemd generator on Linux, which involves creating a malicious script or binary that is typically executed during the system's boot process.
At is a utility for scheduling one-time tasks to run at a specified time in the future on Linux systems.
Attackers can exploit [cron] jobs to run scripts or binaries that establish reverse connections or add reverse shell commands.
A timer unit specifies the schedule and is associated with a corresponding service unit that performs the task.
Persistence can be established through the creation or modification of user accounts.
By placing their public keys in the authorized_keys file, attackers can gain access without requiring further authentication if the private key is in their possession.
Attempt to create a new user with sudo privileges ... add the user to /etc/shadow, /etc/passwd and /etc/group manually.
A web shell is a malicious script uploaded to a web server, enabling attackers to execute arbitrary commands on the host.
Attackers can exploit GRUB’s flexibility and early execution in the boot process to establish persistence. By modifying GRUB configuration files, they can inject malicious parameters or scripts that execute with root privileges before the operating system fully initializes. | Modifying its contents—such as adding malicious scripts or altering initialization logic—enables execution of malicious code before the system fully initializes.
Attackers who can insert overly permissive rules [can] gain unauthorized privileges... an overly permissive policy always returns polkit.Result.YES, which means that any action that requires Polkit’s authentication will be allowed by anyone. | Attackers can replace or add .service files ... to hijack legitimate communication or inject malicious code.
This unit file would attempt to establish a reverse shell connection every time the system boots, running with root privileges.
Git hooks are scripts that Git executes before or after specific events such as commits, merges, and pushes; they are stored in .git/hooks/. | An attacker can set the pager to a command that executes arbitrary code by modifying the core.pager configuration. | When a rule matches, it can trigger a wide range of actions, including executing arbitrary commands or scripts.
Attackers [can] establish persistence on a system by injecting backdoors into these scripts.
By hijacking the package manager's execution flow, attackers can insert malicious code that executes during routine package management tasks, such as package installation or updates.
Adversaries abuse XDG autostart entries to achieve persistence on Linux desktop environments — any .desktop file placed in these directories is automatically executed when a user logs into a graphical session.
To achieve persistence across reboots, a configuration file named panix.conf is created in both /etc/modules-load.d/ and /usr/lib/modules-load.d/. The module is then loaded into the kernel using the insmod command.
By leveraging XDG Autostart, attackers can configure malicious applications to run automatically whenever users log into their desktop environment.
Attackers can hijack system binaries by replacing or backdooring them with malicious counterparts, or manipulate $PATH to prioritize a malicious binary.
The patch introduces a hardcoded backdoor password. Any user who enters the password "_PASSWORD_" will bypass normal password verification and be authenticated successfully. | By providing the path to a backdoor script on the host system, we can ensure that our backdoor is executed on every successful SSH authentication. | Attackers can introduce custom modules or modify existing configurations to manipulate authentication flows, capture credentials, grant unauthorized access, or execute malicious code.
Dynamic MOTD scripts stored in /etc/update-motd.d/ execute shell commands every time a user logs in. | SysV init scripts in /etc/init.d/ are executed with root privileges and can be enabled through update-rc.d to run at boot.
The rc.local script contains commands executed at the end of system boot; systemd-rc-local-generator enables it when /etc/rc.local exists and is executable.
The following analytic detects potential persistence using a systemd generator on Linux, which involves creating a malicious script or binary that is typically executed during the system's boot process.
At is a utility for scheduling one-time tasks to run at a specified time in the future on Linux systems.
Attackers can exploit [cron] jobs to run scripts or binaries that establish reverse connections or add reverse shell commands.
A timer unit specifies the schedule and is associated with a corresponding service unit that performs the task.
Persistence can be established through the creation or modification of user accounts.
By placing their public keys in the authorized_keys file, attackers can gain access without requiring further authentication if the private key is in their possession.
Attackers who can insert overly permissive rules [can] gain unauthorized privileges... an overly permissive policy always returns polkit.Result.YES, which means that any action that requires Polkit’s authentication will be allowed by anyone. | Attackers can replace or add .service files ... to hijack legitimate communication or inject malicious code.
This unit file would attempt to establish a reverse shell connection every time the system boots, running with root privileges.
Git hooks are scripts that Git executes before or after specific events such as commits, merges, and pushes; they are stored in .git/hooks/. | An attacker can set the pager to a command that executes arbitrary code by modifying the core.pager configuration. | When a rule matches, it can trigger a wide range of actions, including executing arbitrary commands or scripts.
Attackers [can] establish persistence on a system by injecting backdoors into these scripts.
By hijacking the package manager's execution flow, attackers can insert malicious code that executes during routine package management tasks, such as package installation or updates.
Adversaries abuse XDG autostart entries to achieve persistence on Linux desktop environments — any .desktop file placed in these directories is automatically executed when a user logs into a graphical session.
To achieve persistence across reboots, a configuration file named panix.conf is created in both /etc/modules-load.d/ and /usr/lib/modules-load.d/. The module is then loaded into the kernel using the insmod command.
By leveraging XDG Autostart, attackers can configure malicious applications to run automatically whenever users log into their desktop environment.
Attackers can abuse process capabilities to maintain persistence by setting specific capabilities on binaries or scripts, allowing a route back to root access.
After setting SUID permissions to the binary, it can be executed in a manner that will allow the user to keep the root privileges.
Adversaries may replace these utilities with backdoored versions to hide malicious activity, harvest credentials, or maintain persistence while appearing to use legitimate system tools.
Attackers can exploit GRUB’s flexibility and early execution in the boot process to establish persistence. By modifying GRUB configuration files, they can inject malicious parameters or scripts that execute with root privileges before the operating system fully initializes. | Modifying its contents—such as adding malicious scripts or altering initialization logic—enables execution of malicious code before the system fully initializes.
D-Bus abuse aligns closely with T1543: Create or Modify System Process, as well as T1574: Hijack Execution Flow for cases where .service files are modified.
Dynamic Linker Hijacking occurs when an attacker manipulates the linking process to redirect execution flow. This can involve altering the library search order through LD_PRELOAD, modifying configuration files like /etc/ld.so.conf, or tampering with cached library mappings in /etc/ld.so.cache.
The patch introduces a hardcoded backdoor password. Any user who enters the password "_PASSWORD_" will bypass normal password verification and be authenticated successfully. | By providing the path to a backdoor script on the host system, we can ensure that our backdoor is executed on every successful SSH authentication. | Attackers can introduce custom modules or modify existing configurations to manipulate authentication flows, capture credentials, grant unauthorized access, or execute malicious code.
The patch introduces a hardcoded backdoor password. Any user who enters the password "_PASSWORD_" will bypass normal password verification and be authenticated successfully. | By providing the path to a backdoor script on the host system, we can ensure that our backdoor is executed on every successful SSH authentication. | Attackers can introduce custom modules or modify existing configurations to manipulate authentication flows, capture credentials, grant unauthorized access, or execute malicious code.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation framework referenced as using Linux udev rule creation for persistence and potential privilege escalation via RUN+= directives in udev rules.
A Linux post-exploitation framework referenced as abusing XDG autostart .desktop entries to establish persistence across reboots, including user-local persistence without root and system-wide persistence when able to write to /etc/xdg/autostart.
Linux persistence simulation tool that can create an LD_PRELOAD execve-hook reverse-shell backdoor, install a persistent loadable kernel-module backdoor, deploy PHP/Python web shells, and backdoor non-interactive system accounts for SSH access.
Linux persistence-testing tool used to establish and test numerous persistence mechanisms, including SysV init, rc.local, MOTD, udev, package-manager hooks/plugins, Git hooks/pagers, process capabilities, and system-binary hijacking. The examples configure reverse-shell payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.