1200KM / simulation
T1574.006 Dynamic Linker Hijacking — Attack Simulation
Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking…
Technique description
Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Shared Library Injection via /etc/ld.so.preload
Procedure 39cb0e67-dd0d-4b74-a74b-c072db7ae991; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dylib Injection via DYLD_INSERT_LIBRARIES
Procedure 4d66029d-7355-43fd-93a4-b63ba92ea1be; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Shared Library Injection via LD_PRELOAD
Procedure bc219ff7-789f-4d51-9142-ecae3397deae; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.