KDE AutoStart Persistence Mechanism Abuse
Adversaries leverage KDE AutoStart scripts and desktop files to achieve persistence on Linux systems by ensuring malicious code executes automatically upon user logon.
Adversaries targeting Linux systems often seek to maintain access across reboots and logons by abusing native desktop environment functionality. The K Desktop Environment (KDE) provides a built-in AutoStart feature, intended to launch user-specified applications or scripts when a session begins. By placing malicious shell scripts (.sh) or desktop configuration files (.desktop) into specific directories - such as ~/.config/autostart/, ~/.kde/Autostart/, or /etc/xdg/autostart/ - an attacker can ensure their payload executes with the privileges of the logged-in user. This technique is a well-documented method for achieving persistence, observed in various threat campaigns. Defenders should monitor for unexpected file creation or modification events within these high-risk AutoStart paths, as legitimate software rarely modifies these locations after initial installation.
Attack Chain
- Attacker gains initial access to the Linux host via exploitation or credential compromise.
- Attacker performs local reconnaissance to identify the desktop environment and user session directories.
- Attacker identifies the appropriate AutoStart directory (e.g., ~/.config/autostart/ or ~/.local/share/autostart/).
- Attacker writes a malicious payload or a script designed to download and execute secondary stages to the target directory.
- Attacker creates or modifies a .desktop file or .sh script to point to the malicious payload, ensuring correct permissions (e.g., chmod +x).
- The victim user logs into their KDE desktop session.
- The KDE session manager automatically executes the malicious script or file, granting the attacker persistence.
Impact
Successful abuse of this technique allows an attacker to maintain a foothold on a compromised Linux system, facilitating ongoing exfiltration of sensitive data, monitoring of user activity, and execution of lateral movement tools. This persistence mechanism is difficult to detect without dedicated monitoring of file system events in specific user configuration directories.
Recommendation
Prioritize the identification of unauthorized modifications to KDE Autostart directories.
- Deploy the provided Sigma rule to monitor file_event activity targeting AutoStart directories.
- Implement periodic auditing of the file system using Osquery to list files in known autostart paths and compare them against a baseline of legitimate entries.
- Investigate any newly created .sh or .desktop files in user home directories for suspicious content, such as encoded commands or external network connection attempts.
- Use file integrity monitoring (FIM) or auditd to alert on any write events to /etc/xdg/autostart/ or user-specific .config/autostart/ paths.
Immediate actions
Deploy Sigma detection rule to monitor KDE Autostart directories
Threat Hunt
Audit existing files in ~/.config/autostart/ and /etc/xdg/autostart/
Data: File listing for autostart directories
Mitigations
Enforce file integrity monitoring (FIM) on user configuration directories.
T1547.001
Detection coverage 1
Detect KDE AutoStart Script or Desktop File Creation
mediumDetects the creation or modification of .sh or .desktop files in known KDE AutoStart directories, which is a common persistence technique.
Detection queries are available on the platform. Get full rules →