Malicious Immutable Flag on SSH authorized_keys via chattr

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-05-15
Updated
2026-08-28

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects use of chattr to set or clear the immutable attribute on an SSH authorized_keys file. Linux intrusion actors inject a backdoor key and then mark authorized_keys immutable so defenders and competing actors cannot remove their persistent access.

Related detections9 linkedT1098.004 — drag to rearrange
Suspicious Making a File Executable in a Temp Directory (via process_creation)
Suspicious SSH authorized_keys Persistence Modification (via process_creation)
Malicious EtherRAT SSH authorized_keys Backdoor Injection via Shell (via process_creation)
Suspicious File Immutability Manipulation via chattr
Malicious UNC4841 SSH Backdoor Persistence via Non-Standard Port and AllowUsers Restriction (via process_creation)
Malicious SSH authorized_keys Modification Following Web Server Compromise (via process_creation)
Suspicious Modification of SSH Authorized Keys on SD-WAN Appliance by UAT-8616
Suspicious Download to tmp Followed by chmod Execution on Linux
Linux: chattr Used to Remove Immutable File Attribute
Malicious Immutable Flag on SSH authorized_keys via chattr
Pivot detection · T1098.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.