Researchers Find Malware Hiding in Windows Subsystem for Linux

A suspicious penguin
(Image credit: Shutterstock)

Black Lotus Labs revealed on Thursday that it's discovered new malware that uses the Windows Subsystem for Linux (WSL) to avoid being detected by security tools.

WSL debuted in 2016 alongside the Windows 10 Anniversary Update as a way to access GNU and Linux tools without having to boot into a different operating system. It didn't originally provide true access to the Linux kernel—it used a compatible kernel developed by Microsoft—but that changed when WSL 2 arrived in June 2019.

Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • garylcamp
    Not clear to me that this malware is on all Windows or is installed by user some how. If user installed, let us know how NOT TO.
    Reply
  • DXRick
    Nathaniel makes it sound like Microsoft did it, instead of hackers exploiting a weakness in WSL, until you read the who article.

    Secondly is bad grammar:

    "Black Lotus Labs revealed on Thursday that it's ... "

    should be: "Black Lotus Labs revealed on Thursday that they... "
    Reply
  • USAFRet
    "The researchers said the malware was distributed via Executable and Linkable Format (ELF) files intended to run on Debian, a popular Linux distribution, and its derivatives. In some cases those files contained a payload intended for a target PC; in others they received a payload from remote command and control infrastructure. "

    So not something in the WSL code, but it seems something the user has downloaded and tried to install.


    DXRick said:
    "Black Lotus Labs revealed on Thursday that it's ... "

    should be: "Black Lotus Labs revealed on Thursday that they... "
    Could also be:
    "Black Lotus Labs revealed on Thursday that it has discovered..."
    Reply