Claude Desktop Cowork VM Boot Image Tampering
Adversaries with user-level access can perform defense evasion by overwriting Claude Desktop Cowork VM boot images to execute malicious code within a virtualized guest.
Claude Desktop features a functionality called 'Cowork' that utilizes a local virtual machine to execute tasks. This VM is booted from a set of image files (kernel, initrd, and root filesystem) stored within the user's application data directory. Because these files are writable by the standard user context and lack integrity verification prior to the boot process, an adversary who has gained user-level access to the host machine can overwrite these images with attacker-controlled versions.
When the user subsequently launches a Cowork session, the virtual machine boots the modified environment. This allows attackers to run arbitrary code inside a sanctioned virtualization container. This technique is particularly dangerous for defense evasion because host-based endpoint detection and response (EDR) solutions often do not inspect activity occurring inside these guest virtual machines by default. This does not grant the attacker elevated privileges on the host itself, but effectively hides malicious activity from standard monitoring visibility.
Impact
Successful exploitation allows attackers to execute arbitrary code within a virtualized, isolated environment, effectively bypassing host-level security monitoring. While this does not grant the attacker direct host administrative privileges, it provides a persistent mechanism to hide malicious guest-side activity from EDR solutions. This threat affects all users of Claude Desktop on Windows and macOS who utilize the Cowork feature.
Recommendation
Detection engineering teams should deploy rules to monitor for unauthorized writes to the Claude vm_bundles directory.
- Enable file integrity monitoring (FIM) or process-based file modification logging on the specific paths listed in the Sigma rule below.
- Investigate any process other than the legitimate
claude.exeorClaudeHelper that attempts to write to thevm_bundlesdirectory. - If tampering is detected, isolate the host and restore the
vm_bundlesdirectory from a known-good backup or by letting the Claude application re-download the verified images. - Hunt for the initial access vector that allowed the unauthorized writer process to execute on the host.
Immediate actions
Deploy the provided Sigma rule to monitor write access to Claude vm_bundles
Threat Hunt
Unauthorized processes writing to Claude vm_bundles directory
Data: File modification logs
Mitigations
Monitor environment for abnormal process activity within user-accessible application data directories
Defense Evasion
Detection coverage 1
Claude Cowork VM Boot Image Tamper
mediumDetects unauthorized modification of Claude Desktop Cowork VM boot images by non-legitimate processes.
Detection queries are available on the platform. Get full rules →