Skidmap

MITRE ATT&CK: S0468 View on attack.mitre.org

Aliases: Skidmap

Malware type
cryptominer, rootkit
Family
Malware family
Operating systems
linux
Profile updated
2026-07-07 15:31:32

Targeted industries: energy-and-utilities

Context

Skidmap is a kernel-mode rootkit used for cryptocurrency mining.

Detection coverage

  • 342 Sigma rules

Malware & tools used

  • Compute Hijacking (attack-pattern)
  • SSH Authorized Keys (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Cron (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Kernel Modules and Extensions (attack-pattern)
  • Pluggable Authentication Modules (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Rootkit (attack-pattern)
  • Process Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Unix Shell (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0468 (report)
  • Trend Micro — Skidmap Linux Malware Uses Rootkit Capabilities To Hide Cryptocurrency Mining Payload (report)

External references