Splunk published a detection analytic for Linux systems that identifies suspicious compiler activity building shared objects with initialization functions, a pattern associated with post-exploitation, persistence, and privilege-escalation tradecraft. The analytic looks for gcc and related compiler processes using flags such as -shared and linker options matching -Wl,-init,* while producing .so output, and it references CVE-2025-32463 as a related concern. The rule is disabled by default, runs hourly when enabled, and depends on EDR or Sysmon for Linux process telemetry mapped into Splunk's Endpoint data model.
The behavior aligns with several MITRE ATT&CK techniques, including Shared Modules (T1129), Stage Capabilities (T1608), and Compile After Delivery (T1027.004). ATT&CK describes adversaries loading malicious functionality through shared libraries and dynamically resolving code at runtime, while staged capabilities can be hosted or prepared on attacker-controlled infrastructure before delivery. Splunk warned that legitimate software development can produce similar compiler activity, so defenders are advised to tune out trusted build workflows while prioritizing unexpected .so compilation with initialization routines on production or non-development Linux hosts.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk updated its detection analytic "Linux Suspicious GCC Invocation Building Init Shared Object," which identifies compiler executions using flags such as "-shared" and "-Wl,-init,*" to build .so files with auto-run initialization functions. The analytic maps this behavior to multiple ATT&CK techniques and references CVE-2025-32463.
MITRE ATT&CK published the Enterprise technique page for Stage Capabilities (T1608), describing how adversaries stage malware, tools, web resources, and certificates on controlled or compromised infrastructure to support later operations.
MITRE ATT&CK published the Enterprise sub-technique page for Obfuscated Files or Information: Compile After Delivery (T1027.004). The reference provides a publication date but no additional event details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.