Security guidance and detection content highlighted a Linux privilege-escalation path in which attackers abuse sudo controls and package-management commands to gain root-level execution. MITRE ATT&CK documents how adversaries can exploit cached sudo credentials, permissive sudoers settings such as NOPASSWD, and configuration options including timestamp_timeout and tty_tickets to run privileged commands without re-authenticating; malware has also been observed modifying /etc/sudoers to weaken terminal-specific protections.
Splunk separately published, and later replaced with a broader analytic, a detection for suspicious use of sudo with apt-get, particularly command lines containing APT::Update::Pre-Invoke, which can be abused to execute arbitrary commands as root. The analytic relied on EDR process telemetry and was intended to surface behavior that, if malicious, could provide full root access and lead to broader system compromise, though Splunk noted the possibility of false positives.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection analytic "Linux apt-get Privilege Escalation" from its content library in version 5.24.0 and replaced it with the broader "Linux APT Privilege Escalation" analytic.
MITRE ATT&CK published the Enterprise sub-technique T1548.003 covering abuse of sudo and sudo credential caching for privilege escalation on Linux and macOS.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.