Compliance Node Overview
MITRE ATT&CK T1574.006 (Dynamic Linker Hijacking) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1574/006/
SHA-256 integrity: 2af1b4354346e775f62b1ad98faa6dd18df11c95bce3dda9d26e0a695f9b4d54
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574.006: Dynamic Linker Hijacking (https://attack.mitre.org/techniques/T1574/006/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access