Glossary
LD_PRELOAD and /etc/ld.so.preload
LD_PRELOAD and /etc/ld.so.preload make the dynamic linker load a chosen shared library first, a hooking technique abused by userland rootkits.
LD_PRELOAD is an environment variable read by the glibc dynamic linker (ld.so). Libraries listed in it are loaded before all others, so their functions take precedence over those in libc. The system-wide equivalent is the file /etc/ld.so.preload, which applies to every dynamically linked program on the host. Developers use the mechanism for debugging and profiling; attackers use it to hook functions such as readdir or open and hide files, processes or network connections from tools like ls, ps and ss. MITRE ATT&CK tracks this as T1574.006, Dynamic Linker Hijacking.
cat /mnt/evidence/etc/ld.so.preload # normally absent or empty
grep -a LD_PRELOAD /proc/*/environ 2>/dev/null
Some limits help detection. For setuid and setgid programs the linker runs in secure-execution mode and ignores most LD_PRELOAD entries. Statically linked binaries are not affected at all, which is why responders carry static tools. Offline analysis of a mounted image also bypasses the hook, because the suspect's linker is not involved. A library path in /etc/ld.so.preload, a recently created .so in an unusual directory, or LD_PRELOAD set in /etc/environment or a shell profile are strong indicators. See hunting Linux persistence and live response through /proc.