Security research

www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks

https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
Published on
www.bleepingcomputer.com

ATT&CK techniques those detections carry

  • T1218System Binary Proxy Execution
  • T1036.005Match Legitimate Resource Name or Location
  • T1112Modify Registry
Open the original

5 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Potential WSL InstallLocation Registry Key ModificationMedium
Suspicious WSL Binary MasqueradingHigh
Suspicious WSL InstallLocation Registry Key Modification Via CommandLineHigh
Suspicious WSL Binary Hijack via Proxy ExecutionHigh
Potential WSL Binary Modification from Installed LocationMedium

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice