Possible AF_ALG Privilege Escalation via algif_aead Module Load

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects loading of the algif_aead kernel crypto module through modprobe or insmod, an autoload step abused by the CVE-2026-31431 Copy Fail local privilege escalation. The exploit drives an AF_ALG splice chain that requires the algif_aead module to reach the vulnerable kernel path. On hosts that do not use userspace crypto the on-demand load of this module is a suspicious precursor to privilege escalation.

Related detections9 linkedT1068 — drag to rearrange
Linux: Detect modprobe-based authencesn crypto module auto-load via kmod
Malicious JuicyPotato Privilege Escalation Execution (UAT-7237)
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Looney Tunables Privilege Escalation Exploit by Kinsing (via process_creation)
Suspicious Kernel Extension Load on macOS (via process_creation)
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Possible AF_ALG Privilege Escalation via algif_aead Module Load
Pivot detection · T1068 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.