Splunk released a Linux anomaly detection analytic for suspicious staging of alternate system files associated with CVE-2025-32463 (chwoot), a local privilege-escalation technique that abuses fake root directories and spoofed configuration files. The analytic looks for creation of sensitive files such as passwd, shadow, sudoers, nsswitch.conf, and libnss libraries outside expected locations, aiming to catch attempts to influence how privileged processes including sudo resolve name services.
The detection uses Endpoint telemetry mapped to the Splunk CIM Filesystem data model and is designed to identify filesystem activity outside normal paths such as /etc and /var/lib/docker. Splunk said the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts because legitimate development, testing, and container-related activity may trigger false positives. Separately, MITRE ATT&CK documents Aoqin Dragon (G1007) as a suspected Chinese cyber-espionage group targeting government, education, and telecommunications organizations in the Asia-Pacific region, though the reference does not tie the group directly to the chwoot detection.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk updated its "Linux Suspicious Staging of Alternate System Files" anomaly detection on 2026-07-08. The analytic is tied to CVE-2025-32463 ("chwoot") and detects suspicious creation of alternate system files and NSS libraries outside normal locations as a potential local privilege escalation technique.
MITRE ATT&CK describes Aoqin Dragon as a suspected Chinese cyber-espionage group active since at least 2013, primarily targeting government, education, and telecommunications organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.