A Memory Data Erasure Technique for Linux Shared Object
Gang Long, Hanlin Yang, Wei Wang, Zhaoxin Zhang, Xiaolong Li, Tengteng Zhao, Jian Wang, Wei Zhang, Tingting Wang, Tingyu Zhang · 2023
Fileless malware and in-memory-only malicious payloads have become a trend of cyberthreat. To perform a stealthy and traceless infiltration, threat actors and security researchers have presented several anti-forensic techniques for memory-resident payloads, mostly focusing on hiding the memory data from being detected by forensic tools. In this paper, we take another direction to think about erasing the artifact from the memory so no trace is left behind. We propose a self-deletion and self-unloading technique for a malicious payload compiled as a Linux shared object, to destruct its memory data when needed, which can be used in combination with in-memory execution and process injection techniques to launch a fileless and traceless attack. As is proved by the experiment, after the shared object containing the malicious payload is self-destructed using our technique, all its data are removed from the memory of the victim machine without any remains. To prevent its misuse, we also provide suggestions for system managers and incident responders on mitigating and detecting the abuse of this technique.