Diamorphine is an open-source Linux loadable kernel module rootkit used to conceal malicious activity and manipulate process privileges on compromised systems. Its capabilities include hiding processes, concealing its own kernel module, hiding files and directories with a configured name prefix, and granting root privileges to a process. It intercepts directory-enumeration and signal-related system calls, including getdents, getdents64, and kill, by replacing syscall-table handler pointers. Special kill signals act as covert controls for hiding and privilege manipulation. Modern versions have used a kprobe-based technique to resolve otherwise unexported kernel symbols.
TeamTNT has repeatedly deployed Diamorphine to hide cryptocurrency miners, including XMRig, in attacks against Linux servers, cloud instances, and misconfigured Docker environments. Deployment commonly follows initial compromise: shell scripts download or unpack the rootkit source, compile it on the victim, and load the resulting kernel module. Observed deployment chains include privileged containers and compromised cloud VPS hosts. Loading the module requires sufficient kernel-module privileges and compatibility with the target kernel; its privilege-granting functionality is not itself an initial-access exploit.
Diamorphine serves as a kernel-level stealth component within broader intrusion toolchains rather than performing cryptocurrency mining or credential theft itself. Its traditional syscall-table hooking approach is constrained on x86-64 Linux kernel 6.9 and later, where syscall dispatch no longer uses that table to invoke handlers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group started using a Linux Kernel Module (LKM) rootkit named Diamorphine to hide their activities on infected machines.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The signal SIGSUPER = 64 obtains root privileges by committing new credentials with uids = 0.
“By overwriting a pointer in this table, an attacker can redirect a legitimate syscall, such as getdents64, kill, or read, to a malicious handler.” | “Rootkits are stealthy malware designed to conceal malicious activity, such as files, processes, network connections, kernel modules, or accounts.” | “A recent update to Diamorphine used this technique. It places a kprobe to grab the pointer of kallsyms_lookup_name itself.”
Stripping binaries and appending a single null byte significantly degraded static detections; limited XOR string/configuration encoding and lightweight packing were also used.
This empowers a rootkit to filter the output of the ls command to hide malicious files or prevent a specific process from being terminated.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel rootkit discussed as using unusual kill signals and as detectable through kernel module loading telemetry such as finit_module/init_module syscall monitoring.
Kernel-module Linux rootkit whose loading can be detected through init_module/finit_module syscall telemetry; it can use unusual high-numbered kill signals as covert triggers.
Mentioned solely as an example of a modern rootkit associated with the kprobe trick for resolving kallsyms_lookup_name on newer Linux kernels.
Linux loadable-kernel-module rootkit that hooks system calls, disables CR0 write protection to alter kernel behavior, and can use kprobes to resolve hidden symbols.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.