libprocesshider is an open-source Linux user-space rootkit designed to conceal selected processes from common process-enumeration utilities, including ps, top, and lsof. It operates as a shared library loaded through the Linux dynamic linker's preload mechanism rather than as a kernel module. The library interposes the libc readdir and readdir64 functions, identifies process entries during enumeration of the Linux process filesystem, and suppresses entries whose process names match a configured filter. Nonmatching entries are returned normally. Its concealment affects utilities relying on the intercepted functions; it does not remove the underlying processes from the kernel.
System-wide deployment uses the dynamic linker's preload configuration, modification of which requires root privileges. libprocesshider serves as a concealment component installed after compromise, rather than an initial-access mechanism. TeamTNT has used it to hide Tsunami bot and XMRig mining processes in Linux and cloud-container campaigns. The Xanthe cryptomining botnet also deploys it to conceal its XMRig payload. A modified version appeared in the toolkit associated with DarkRadiation Linux ransomware. It has additionally been used by UAC-0133, assessed as a Sandworm/APT44 subcluster, in operations against Ukrainian energy, water, and heat-supply organizations. These uses demonstrate its adoption across both financially motivated and state-linked intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
libprocesshider - An open-source tool that uses the ID preloader to hide a process under Linux.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Every process with this name will be excluded ... static const char* process_to_filter = "evil_script.py"; ... if(get_dir_name(dirp, dir_name, sizeof(dir_name)) && strcmp(dir_name, "/proc") == 0 && get_process_name(dir->d_name, process_name) && strcmp(process_name, process_to_filter) == 0) { continue; }
Every process with this name will be excluded ... strcmp(process_name, process_to_filter) == 0) { continue; }
Rocke downloaded a file "libprocesshider", which could hide files on the target system.
Libprocesshider is an open-source tool designed to hide specific processes from commonly used process-listing tools such as ps, top, and lsof by overwriting the readdir function. This technique enabled TeamTNT to conceal XMRig cryptomining and other malicious processes.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A userland process-hiding tool abused by TeamTNT via LD_PRELOAD to conceal malicious processes such as Tsunami.
An open-source LD_PRELOAD-based process-hiding tool that intercepts readdir to conceal specified processes from process-listing utilities including ps, top, and lsof. TeamTNT used it to conceal cryptomining and other malicious processes.
Linux process-hiding tool used by TeamTNT to conceal processes. The report lists it among tools introduced during the January 2021 Kubernetes activity.
A Linux rootkit used here in modified form as part of the attacker toolset to hide processes on infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.