New Malware Variant Attacks Through Wsl Vulnerabilities

New Malware Variant Attacks Through Wsl Vulnerabilities

The completely new variant of malware distribution says not only about the professionalism of its creators. Possibly we are spectating another serious security breach in Windows. A lot of users, and especially developers, were happy to see the Windows Subsystem for Linux. After 5 years of being successfully used on Windows, no one expected that this thing could turn into a hazard.

Linux malware for Windows?

Windows Subsystem for Linux (shortly WSL) is an integrated environment in Windows. This subsystem allows the operating system to launch and use the applications for Linux (primarily – for Debian-like distributions). This “compatibility layer” allows you to minimize the efforts needed for launching the Linux programs on your PC. Previously, users were using dual-boot or virtual machines for this purpose.

Such close relations between Windows and Linux, that is run under WSL, require simplified access to the storage devices. While running Linux on both virtual machine or dual boot, you have your Windows root directory (and all Windows-related files) isolated. Using the WSL allows you to control your disks from both systems simultaneously. And this ability, exactly, is a security breach, that allows the crooks to inject malware without any risks of being detected.

Malware injection through WSL: how it works?

Malicious items that were detected first by Black Lotus Labs are, in fact, small ELF files, that were acting as downloaders. After launching into the WSL environment, they connect to the command server and get the payload. It seems that this malware was designed for some specific conditions. This conclusion appeared in the Black Lotus Labs report, when they saw that no malware has been downloaded. But surely, the fact that an initial virus has successfully connected to the command server clearly shows its abilities.

WSL malware was not detected at all (as of 09/16)

The thing that shocked the cybersecurity analysts is that this malware is almost ignored by anti-malware engines. As of 09/21, only 6 antivirus programs detected it, among more than 5 dozen ones present on VirusTotal. Even Microsoft Defender, which works on a very deep level into the system, and must see those manipulations, is not able to detect this threat.

David Miller
Author

David Miller

David Miller brings 15 years of experience in global economics, personal finance strategy, and market dynamics. He specializes in turning complex economic trends into actionable insights for everyday readers.