Settings

Theme

APT36 hackers abuse Linux .desktop files to install malware in new attacks

bleepingcomputer.com

10 points by Santosh83 5 months ago · 2 comments

Reader

like_any_other 5 months ago

> Victims receive ZIP archives through phishing emails containing a malicious .desktop file disguised as a PDF document, and named accordingly.

How does the disguise work?

  • hdgvhicv 5 months ago

    Some desktop environments hide file extensions. This bad behaviour dates back 30 years.

    File is foo.pdf.desktop in a zip file. zip unzipped, DE hides .desktop and shows “foo.pdf”

    User double clicks thinking it’s a safe pdf but it’s actually a script or other payload which does bad things.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection