Potential Hijacking of Windows Subsystem for Linux via Registry Modification
Adversaries can gain persistence and perform proxy execution by modifying the WSL InstallLocation registry key to redirect binary execution to malicious payloads.
Research indicates that the Windows Subsystem for Linux (WSL) configuration can be abused by attackers to achieve stealthy execution and persistence. By modifying the 'InstallLocation' registry key associated with WSL, an actor can point the system to a custom or malicious directory. When a user subsequently invokes 'wsl.exe' or 'bash.exe', the system executes the payload located at the path defined in the hijacked registry key instead of the legitimate WSL environment. This technique provides a mechanism for defense evasion by leveraging trusted system binaries to execute malicious code, potentially bypassing security controls that rely on process allowlisting or signature-based detection. This method has been documented in various security research reports as a vector for stealthy operations and long-term system persistence on Windows endpoints.
Attack Chain
- Attacker gains initial access or code execution on the target Windows system.
- Attacker identifies the WSL 'InstallLocation' registry key path under 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Lxss'.
- Attacker drops a malicious binary or script designed to masquerade as the legitimate WSL environment.
- Attacker modifies the 'InstallLocation' registry value to point to the directory containing the malicious payload.
- The next time the user or an automated task executes 'wsl.exe' or 'bash.exe', the system loads the malicious files instead of the legitimate WSL components.
- The malicious payload executes within the context of the WSL process, achieving the attacker's objective (persistence, exfiltration, or further command execution).
Impact
Successful exploitation allows attackers to maintain stealthy persistence and execute malicious code under the guise of legitimate system processes. This can lead to unauthorized access to sensitive data, internal network reconnaissance, and the deployment of additional malware, impacting the integrity and confidentiality of the host system.
Recommendation
- Deploy the provided Sigma rule to monitor for unauthorized modifications to the WSL 'InstallLocation' registry key.
- Establish a baseline of expected 'InstallLocation' paths within the environment to facilitate more precise alerting.
- Review registry monitoring logs (Event ID 13) for unexpected processes modifying keys under 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Lxss'.
- Restrict administrative privileges on endpoints to prevent unauthorized registry modifications.
Immediate actions
Deploy Sigma detection rule to SIEM and monitor for hits on WSL registry keys.
Threat Hunt
Search historical registry modification logs for changes to the Lxss\MSI path.
Data: Registry Set (Event ID 13)
Detection coverage 1
Detect Potential WSL InstallLocation Registry Key Modification
mediumDetects modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key, which can be used for proxy execution or persistence.
Detection queries are available on the platform. Get full rules →