ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

New Malware Targeting Windows Subsystem for Linux

Christi by Christi
June 3, 2022 - Updated on June 4, 2022
in Malware
Reading Time: 3 mins read
Windows Subsystem for Linux
Share on FacebookShare on Twitter

New threats are on the rise with operating systems becoming increasingly interoperable. Corporate environments using Windows Subsystem for Linux (WSL) need to be wary. Black Lotus Labs has discovered threat actors utilizing Linux binaries or compiled source code as loaders in the WSL.

WSL security threats and what they mean

Security threats impacting the Windows Subsystem for Linux are becoming increasingly common. The WSL seems to be a nice feature, but it comes with its own set of problems that may not be obvious at first.

When you use Linux in Windows, you are actually running an environment on top of Windows. This is what allows you to run Linux applications directly in Windows without having to reboot into Linux. It also means that if anything goes wrong in the Linux environment, your entire system can be compromised by an attacker who gains access to it.

Recently, Black Lotus Labs outlined how they were able to fish samples related to various kinds of endpoint and network access using open-source tools as well as custom-developed tools by threat actors. And this is just the beginning.

In fact, threat actors are finding new and ingenious ways and workarounds to gaining unauthorized access to computer networks and endpoints. Research in this area is scant, which makes things even riskier.

Threats to look out for

As per the researcher’s results, here are the notable samples Black Lotus Labs found:

  • Keyjeek (1/60 detection rate on VirusTotal) – a Keylogger that logs keystrokes, and mouse events and uses hardcoded Gmail credentials to send the records back to the attacker (nomotikag33n[AT]gmail.com).
  • Shellcode injector – a shellcode downloader and executer, this sample showed promise of the ability to download more sophisticated agents like Cobalt Strike (or custom frameworks). As the agent is not being written on the disk but is injected directly into memory, it makes host-based detection very unlikely.
  • Stub.py Stager – A more traditional stager, this sample (currently in development as per Black Lotus Labs as it uses a non-routable IP address) runs as a Python script in the bash terminal and connects to a remote resource. It then downloads an executable as a Python script (to further avoid detection) and changes the file extension to an executable (.exe) after decrypting it using a hardcoded key. The payload is then copied to the Windows startup folder, thus becoming persistent between reboots.
  • Lee agent – A logic agent that contains functions such as file upload/download, zip, persist, screenshot, run cmd, python, install, exit, clean, and crack, it is the closest to being functional as per Black Lotus Labs.

Notable open-source tools and modules they found:

  • DiscordRAT (3/61 detection rate on VirusTotal) – a Discord-controlled RAT (remote administration tool) that included 20+ commands.
  • Discord Token Grabber (9/62 detection rate on VirusTotal) – A token grabber that harvests auth tokens that web browsers save on the disk including Chrome, Opera, Brave, Yandex, and Discord. The tokens are then sent to a Discord account operated by the actor.

    Windows Subsystem for Linux-Discord hack
    Discord Token grabber sample screenshot, Source: Black Lotus Labs
  • You might also like

    Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

    Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

    DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

  • Keylogger (9/62 detection rate on VirusTotal) – A Discord-based keylogger that sends data from the host to the C2 via a Discord URL. It does not write data to the disk, thereby making it very hard for the host to detect it.
  • Telegram-based bot (RAT) – this bot utilized the Telegram API (in contrast to Discord seen so far) and worked as a RAT.
  • Password Dumper (0 detection rate on Virus Total) – This one is more of a Proof-of-Concept to retrieve passwords, but did not communicate with external agents. When done the right way, this one could potentially harvest stored credentials (this agent was supposed to harvest the Chrome login database). This cannot be detected as it uses no third-party services (like Discord).

Where do we go now?

Black Lotus Labs followed and is still following the WSL attack surface to detect such threats. They also recommend the larger information security community do the same. Major players in the industry are coming together to fight against WSL-based attacks.

WSL is essentially a compatibility layer that allows Linux applications to run on Windows. It is not a virtual machine or an emulator — it is a native execution environment for Linux binaries. This means that any malware written for Linux can run on WSL without any modifications required.

The WSL is a very powerful feature that allows developers to run Linux command-line tools directly on Windows without any additional software or configuration changes. Unfortunately, this also makes it an attractive target for hackers who want to use it as a backdoor into your computer.

Source: Black Lotus Labs
Tags: linuxWindows Subsystem for LinuxWSL
Previous Post

Follina Exploit Being Deployed by Chinese APT Group TA413

Next Post

LuoYu Hacker Collective using New Techniques to Deploy WinDealer Backdoor

Christi

Christi

Christi began her InfoSec carrier at the Illinois Institute of Technology where she received her Bachelor of Science degree in Applied Cybersecurity and Information Technology. Her passions include learning about new threats, data breaches, running, and playing with her dog, Pablo.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.