Threat Intelligence

Covert Windows systems compromise facilitated by WSL2 exploitation

Microsoft March Patch Tuesday roundup

Windows systems could be stealthily infiltrated through the abuse of Windows Subsystem for Linux 2 virtual machines, Cyber Security News reports.

Threat actors could inject a beacon object file into any installed WSL2 distro, which operates as its own Hyper-V VM, to execute arbitrary commands and read files, as well as transition to Linux environments without triggering security alerts, a report from SpecterOps researchers revealed. With the $WSL share not scanned by multiple security tools, attackers could easily execute Linux utilities that help enable compromise while evading security tools, extending dwell times and incident probes.

Numerous existing alerting rules are also being deteriorated by the exploitation of WSL2, according to researchers, who noted that only a short wsl.exe process is being viewed by defenders rather than dubious drivers and Windows services. Such findings should prompt the implementation of extended WSL2 activity monitoring and logging activities.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds