Skip to content

S0468 Skidmap

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.1

Item Value
ID S0468
Associated Names
Type MALWARE
Version 1.0
Created 09 June 2020
Last Modified 26 June 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1098 Account Manipulation -
enterprise T1098.004 SSH Authorized Keys Skidmap has the ability to add the public key of its handlers to the authorized_keys file to maintain persistence on an infected host.1
enterprise T1547 Boot or Logon Autostart Execution -
enterprise T1547.006 Kernel Modules and Extensions Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.1
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.004 Unix Shell Skidmap has used pm.sh to download and install its main payload.1
enterprise T1140 Deobfuscate/Decode Files or Information Skidmap has the ability to download, unpack, and decrypt tar.gz files .1
enterprise T1083 File and Directory Discovery Skidmap has checked for the existence of specific files including /usr/sbin/setenforce and /etc/selinux/config. It also has the ability to monitor the cryptocurrency miner file and process. 1
enterprise T1562 Impair Defenses -
enterprise T1562.001 Disable or Modify Tools Skidmap has the ability to set SELinux to permissive mode.1
enterprise T1105 Ingress Tool Transfer Skidmap has the ability to download files on an infected host.1
enterprise T1036 Masquerading -
enterprise T1036.005 Match Legitimate Name or Location Skidmap has created a fake rm binary to replace the legitimate Linux binary.1
enterprise T1556 Modify Authentication Process -
enterprise T1556.003 Pluggable Authentication Modules Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users.1
enterprise T1027 Obfuscated Files or Information Skidmap has encrypted it’s main payload using 3DES.1
enterprise T1057 Process Discovery Skidmap has monitored critical processes to ensure resiliency.1
enterprise T1496 Resource Hijacking Skidmap is a kernel-mode rootkit used for cryptocurrency mining.1
enterprise T1014 Rootkit Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.1
enterprise T1053 Scheduled Task/Job -
enterprise T1053.003 Cron Skidmap has installed itself via crontab.1
enterprise T1518 Software Discovery -
enterprise T1518.001 Security Software Discovery Skidmap has the ability to check if /usr/sbin/setenforce exists. This file controls what mode SELinux is in.1
enterprise T1082 System Information Discovery Skidmap has the ability to check whether the infected system’s OS is Debian or RHEL/CentOS to determine which cryptocurrency miner it should use.1

References