Linux XDG Autostart Persistence Mechanism
Adversaries, including those using the PANIX post-exploitation framework, are abusing XDG autostart directories on Linux to achieve persistence via malicious .desktop files.
Adversaries targeting Linux environments are leveraging XDG autostart directories to establish persistence by creating or modifying .desktop files. These directories, specifically /etc/xdg/autostart for system-wide configuration and ~/.config/autostart for user-specific sessions, are monitored by Linux desktop environments to automatically execute applications upon user login. This technique is utilized by various post-exploitation frameworks, such as PANIX, to maintain access across reboots. By placing a malicious .desktop file in these locations, an attacker ensures their payload executes with the privileges of the logged-in user. Defenders should prioritize monitoring for file creation events within these specific paths to identify unauthorized persistence attempts, while filtering against legitimate software installations that utilize these paths for standard application startup.
Attack Chain
- Attacker gains initial access to the Linux system using an exploit or compromised credentials.
- Attacker performs local reconnaissance to identify the user's desktop environment and home directory.
- Attacker stages a malicious payload (e.g., a script or binary) on the file system.
- Attacker crafts a malicious .desktop file that references the staged payload in the Exec field.
- Attacker writes the .desktop file to the ~/.config/autostart/ directory for user-local persistence.
- Attacker optionally writes to /etc/xdg/autostart/ if root privileges were obtained for system-wide persistence.
- Attacker waits for the user to log into their graphical desktop session.
- Desktop environment automatically parses the .desktop file and executes the malicious payload, re-establishing access for the attacker.
Impact
Successful exploitation allows for long-term persistence on Linux desktop environments, enabling attackers to maintain command-and-control access after system reboots. This technique effectively bypasses simple session-based defenses and ensures that malicious code runs with the context and permissions of the targeted user upon every login.
Recommendation
- Implement file integrity monitoring for the paths /etc/xdg/autostart/ and ~/.config/autostart/ to alert on the creation of any .desktop file.
- Deploy the provided Sigma rule to ingest Sysmon for Linux file creation events and correlate them with process execution telemetry.
- Establish an allowlist for known-good software deployment tools that legitimately modify autostart directories to reduce false positive noise.
- Audit existing .desktop files in these directories for suspicious Exec commands that deviate from standard installed application paths.
Immediate actions
Deploy file monitoring for /etc/xdg/autostart/ and ~/.config/autostart/ paths.
Threat Hunt
Audit current contents of XDG autostart directories for non-standard binaries.
Data: File list of /etc/xdg/autostart/ and ~/.config/autostart/
Detection coverage 1
Detect Suspicious XDG Autostart File Creation
mediumDetects the creation of .desktop files within standard XDG autostart directories, which is a common persistence technique on Linux.
Detection queries are available on the platform. Get full rules →