Skip to content
Threat Feed
medium advisory

Claude Desktop Cowork VM Boot Image Tampering

Adversaries with user-level access can perform defense evasion by overwriting Claude Desktop Cowork VM boot images to execute malicious code within a virtualized guest.

Claude Desktop features a functionality called 'Cowork' that utilizes a local virtual machine to execute tasks. This VM is booted from a set of image files (kernel, initrd, and root filesystem) stored within the user's application data directory. Because these files are writable by the standard user context and lack integrity verification prior to the boot process, an adversary who has gained user-level access to the host machine can overwrite these images with attacker-controlled versions.

When the user subsequently launches a Cowork session, the virtual machine boots the modified environment. This allows attackers to run arbitrary code inside a sanctioned virtualization container. This technique is particularly dangerous for defense evasion because host-based endpoint detection and response (EDR) solutions often do not inspect activity occurring inside these guest virtual machines by default. This does not grant the attacker elevated privileges on the host itself, but effectively hides malicious activity from standard monitoring visibility.

Impact

Successful exploitation allows attackers to execute arbitrary code within a virtualized, isolated environment, effectively bypassing host-level security monitoring. While this does not grant the attacker direct host administrative privileges, it provides a persistent mechanism to hide malicious guest-side activity from EDR solutions. This threat affects all users of Claude Desktop on Windows and macOS who utilize the Cowork feature.

Recommendation

Detection engineering teams should deploy rules to monitor for unauthorized writes to the Claude vm_bundles directory.

  • Enable file integrity monitoring (FIM) or process-based file modification logging on the specific paths listed in the Sigma rule below.
  • Investigate any process other than the legitimate claude.exe or Claude Helper that attempts to write to the vm_bundles directory.
  • If tampering is detected, isolate the host and restore the vm_bundles directory from a known-good backup or by letting the Claude application re-download the verified images.
  • Hunt for the initial access vector that allowed the unauthorized writer process to execute on the host.

Immediate actions

Deploy the provided Sigma rule to monitor write access to Claude vm_bundles

Detection Engineering 48h

Threat Hunt

Unauthorized processes writing to Claude vm_bundles directory

T1564.006 high high confidence hunt now

Data: File modification logs

Mitigations

Monitor environment for abnormal process activity within user-accessible application data directories

short_term SOC

Defense Evasion

Detection coverage 1

Claude Cowork VM Boot Image Tamper

medium

Detects unauthorized modification of Claude Desktop Cowork VM boot images by non-legitimate processes.

sigma tactics: defense_evasion techniques: T1564.006 sources: file_event, windows

Detection queries are available on the platform. Get full rules →