A Linux process-hiding technique can make active malware disappear from common process-listing tools by bind-mounting a spoofed directory over /proc/[pid]. In a demonstration against a Sliver beacon, the implant continued running and communicating with its command-and-control server even after its /proc entry was obscured, causing utilities such as ps to lose visibility because they rely on files like /proc/[pid]/stat, /proc/[pid]/status, and /proc/[pid]/cmdline.
The method exploits Linux procfs behavior to interfere with userland inspection rather than stopping the process itself. Defenders can still hunt for artifacts including anomalous entries in /proc/mounts, empty or abnormal contents under /proc/[pid], and unusual writable permissions on a PID directory, while network evidence may remain visible through sources such as /proc/net/tcp, netstat, and nf_conntrack even when direct process attribution disappears.
![Bind-Mount Trick Hides Linux Processes by Spoofing `/proc/[pid]`](/_next/image?url=https%3A%2F%2Fmallory-core-public-images.s3.us-east-2.amazonaws.com%2Fbind-mount-trick-hides-linux-processes-by-spoofing-procpid.png&w=3840&q=75)
Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A DFIR blog post demonstrated a Linux process-hiding technique that bind-mounts a spoofed directory over a live /proc/[pid] entry, causing tools such as ps to stop showing the target process while it continues running. The post used a Sliver beacon as the example and documented forensic indicators including anomalous /proc/mounts entries, abnormal PID-directory permissions, and surviving network artifacts in netstat, /proc/net/tcp, and nf_conntrack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.