Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
APT36 Uses .desktop Files for Malware Installation - News Directory 3

APT36 Uses .desktop Files for Malware Installation

August 24, 2025 Lisa Park Tech
News Context
At a glance
Original source: bleepingcomputer.com

APT36 Cyberspies target Indian Government with Novel Linux Malware attack

Table of Contents

  • APT36 Cyberspies target Indian Government with Novel Linux Malware attack
    • Desktop File⁤ Abuse: A Clever Disguise
    • Bypassing Security Measures
    • A ⁢growing Threat

New Delhi, India – A complex cyber espionage campaign targeting Indian⁢ government and defense entities has been uncovered, revealing a novel⁤ tactic employed by the Pakistani APT36 group.Security researchers at Cyfirma and CloudSEK have documented the attacks, which leverage malicious Linux.desktop files to deliver malware and establish persistent access for data exfiltration.

The attacks, first detected on August 1, 2025, are⁤ ongoing, highlighting the persistent threat posed by APT36. This ⁢campaign marks a significant evolution in the group’s tactics, demonstrating increased sophistication and evasion techniques.

Desktop File⁤ Abuse: A Clever Disguise

The attackers are using phishing ⁤emails containing ZIP archives. These‍ archives contain⁢ a malicious .desktop file disguised⁢ as a PDF document.Linux.desktop files are typically plain-text application launchers, defining an icon, ⁢name, and command ‍to execute when the user clicks it. Though, in these attacks, the .desktop file is weaponized. When a user opens the file, believing it to be a PDF, a hidden bash command executes. This command fetches a hex-encoded payload from the attacker’s⁢ server or Google Drive,‍ saves ⁢it⁤ to a temporary file, makes it executable, and then ⁤runs it in the background.

To further deceive the victim, the script also ⁤launches Firefox to display a benign decoy PDF file hosted on Google Drive.

The attackers manipulate the ‘Exec=’ field to run a sequence of shell ⁣commands. They also add fields like ‘Terminal=false’ to hide the terminal ⁣window and ‘X-GNOME-Autostart-enabled=true’ to ensure the file runs at every login.

Bypassing Security Measures

Because .desktop files on Linux‍ are typically text-based and their abuse is not widely documented, security tools ⁤are unlikely to monitor them as potential threats. This allows the attackers to bypass customary security measures.

The payload ⁢dropped by the ⁣malformed ⁤.desktop file is a Go-based ELF executable ⁤designed for espionage. It‍ can remain hidden or⁤ establish persistence using cron ⁣jobs and systemd services. Interaction with the command-and-control (C2) server is facilitated through a bi-directional WebSocket channel, enabling data exfiltration and remote command execution.

A ⁢growing Threat

This campaign highlights⁣ the evolving threat landscape and the need for increased vigilance. As APT36 continues to refine its tactics, organizations must adopt proactive security measures to detect and prevent these types of‍ attacks.

The use of .desktop files as a ⁣malware delivery‍ mechanism is a concerning trend, as it exploits a lesser-known vulnerability in the Linux environment. Security professionals‍ must educate users about the risks associated with opening suspicious ⁣files, even if they appear to‍ be harmless ⁤documents.

The ongoing nature of these⁣ attacks underscores the importance of continuous‍ monitoring and ⁣threat intelligence sharing. By ⁣working together, organizations can better protect themselves from the ever-evolving tactics of APT36 and other cyber espionage groups.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Worth a look

  • Samsung Galaxy S27 Ultra leaks point to a redesigned camera island
  • Yadullah Abidi compares Claude and Gemini on Android apps

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com