Potential WSL Binary Modification from Installed Location

 Original Source: [Sigma source]
Title: Potential WSL Binary Modification from Installed Location
Status: experimental
Description:Detects the modification of the wsl.exe binary from its installed location. Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
References:
  -https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
  -https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
  -https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
  -https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
  -https://learn.microsoft.com/en-us/windows/wsl/
Author: Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2026-05-05
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1036.005'
  • -'attack.t1218'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection_wsl_exe:
    TargetFilename|endswith: '\wsl.exe'
  selection_wsl_folder:
    - TargetFilename|contains:
      - ':\Program files\wsl\'
      - ':\Program files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_'
    - TargetFilename|contains|all:
      - ':\Users\'
      - '\AppData\Local\Microsoft\WindowsApps\'
  filter_main_msiexec:
    Image:
      -'C:\Windows\System32\msiexec.exe'
      -'C:\Windows\SysWOW64\msiexec.exe'

  filter_main_svchost:
    Image: 'C:\Windows\System32\svchost.exe'
    TargetFilename|contains: '\WindowsApps\'
  condition:all of selection_* and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: medium