New Malware Variant Employs Windows Subsystem for Linux for Attacks

This article has been indexed from E Hacking News – Latest Hacker News and IT Security News

 

Security experts have found a new malware variant that uses Windows Subsystem for Linux to infect systems covertly. The research highlights that malicious actors explore new attack tactics and focus on WSL to avoid being detected. 
Black Lotus Labs, the Lumen Technologies networking threat research organization, reported on Thursday 16th of September claimed that it has detected many malicious Python files in Debian Linux’s binary ELF (Executable and Linkable) format. 
The initial samples were found at the beginning of May for the WSL environment and lasted until August 22 every 2 to 3 weeks. These function as WSL loaders and can be detected extremely poorly in public file scanning services. The next step is the injection of malWindows API calls into an ongoing process, a method that is neither new nor advanced. 
Of the few discovered instances, only one has been given a publicly routable IP address, indicating that attackers concerned are testing WSL for malware installation on Windows. The malevolent files mostly rely on Python 3 to perform their duties and are bundled with PyInstaller as ELF for Debian. 
“As the negligible detection rate on VirusTotal suggests, most endpoint agents designed for Windows systems don’t have signatures built to analyze ELF files, though they frequently detect non-WSL agents with similar functionality” Black Lotus Labs told. 
Just over a month ago, only one VirusTotal antivirus engine recognized a dangerous Linux file. Updating the scan fo

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: New Malware Variant Employs Windows Subsystem for Linux for Attacks