Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
1–10 of 44 posts
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#2Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#3Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#4Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#5Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
See: https://docs.microsoft.com/en-us/windows/wsl/install-win10
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#6Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#7Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#8Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
Yes, and I believe enabling it requires administrative rights so the risk to a lot of organizations with locked down Windows installs is minimal unless they’ve enabled WSL intentionally
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#9Is WSL still opt-in? Something to be aware of for power users, but most Windows users are never going to know about or figure out how to turn on WSL (at least as of the last time I tried it).
Yes, and I believe enabling it requires administrative rights so the risk to a lot of organizations with locked down Windows installs is minimal unless they’ve enabled WSL intentionally
Re: Black Lotus Labs uncovers Linux executables deployed as stealth Windows loaders
#10But since WSL 2 it does use a VM. According to wikipedia:
"a real Linux kernel,[4] through a subset of Hyper-V features." "with a Linux kernel running in a lightweight virtual machine environment."
edit: unless they mean user overhead of getting it to work. I kind of read it as performance overhead.