Skip to content
Threat Feed
medium advisory

Windows Subsystem for Linux Binary Hijacking

Adversaries may modify the wsl.exe binary within its installation directory to facilitate proxy execution and achieve defense evasion.

Adversaries are known to leverage the Windows Subsystem for Linux (WSL) as a vector for stealthy operations. A specific technique identified involves the replacement or modification of the legitimate wsl.exe binary located within its default installation path. By substituting the genuine executable with a malicious payload, an attacker can ensure their code executes whenever a user or automated process attempts to launch a Linux environment. This technique facilitates proxy execution, allowing the malicious payload to run within the context of an expected system binary, thereby aiding in defense evasion and persistence. Defenders should monitor file modification events targeting the wsl.exe path to detect unauthorized tampering with core WSL infrastructure.

Impact

Successful hijacking of the wsl.exe binary allows an attacker to execute arbitrary code with the privileges of the user invoking the WSL environment. This can lead to full system compromise, exfiltration of sensitive data from the Linux subsystem, or the establishment of a stealthy backdoor that remains active as long as the WSL environment is utilized by the victim.

Recommendation

Deploy file integrity monitoring (FIM) or file creation event logging to detect modifications to wsl.exe. Enable the provided Sigma rule to alert on unauthorized file writes to the WSL application directories. Investigate any process modification events where wsl.exe is the target, excluding known-good update processes initiated by msiexec.exe or legitimate service host activity.


Immediate actions

Deploy the Sigma rule to monitor for unauthorized modifications to wsl.exe

Detection Engineering 48h

Threat Hunt

Search file audit logs for any modification of wsl.exe not originating from trusted installer processes

T1036.005 medium high confidence hunt now

Data: File integrity logs

Mitigations

Implement strict file system permissions on the WSL installation directories to prevent unauthorized write access

medium IT Operations

Detection coverage 1

Potential WSL Binary Modification from Installed Location

medium

Detects the modification of the wsl.exe binary from its installed location, which may indicate binary hijacking for proxy execution.

sigma tactics: stealth techniques: T1036.005, T1218 sources: file_event, windows

Detection queries are available on the platform. Get full rules →