APT36 Uses .desktop Files for Malware Installation
APT36 Cyberspies target Indian Government with Novel Linux Malware attack
Table of Contents
New Delhi, India – A complex cyber espionage campaign targeting Indian government and defense entities has been uncovered, revealing a novel tactic employed by the Pakistani APT36 group.Security researchers at Cyfirma and CloudSEK have documented the attacks, which leverage malicious Linux.desktop files to deliver malware and establish persistent access for data exfiltration.
The attacks, first detected on August 1, 2025, are ongoing, highlighting the persistent threat posed by APT36. This campaign marks a significant evolution in the group’s tactics, demonstrating increased sophistication and evasion techniques.
Desktop File Abuse: A Clever Disguise
The attackers are using phishing emails containing ZIP archives. These archives contain a malicious .desktop file disguised as a PDF document.Linux.desktop files are typically plain-text application launchers, defining an icon, name, and command to execute when the user clicks it. Though, in these attacks, the .desktop file is weaponized. When a user opens the file, believing it to be a PDF, a hidden bash command executes. This command fetches a hex-encoded payload from the attacker’s server or Google Drive, saves it to a temporary file, makes it executable, and then runs it in the background.
To further deceive the victim, the script also launches Firefox to display a benign decoy PDF file hosted on Google Drive.
The attackers manipulate the ‘Exec=’ field to run a sequence of shell commands. They also add fields like ‘Terminal=false’ to hide the terminal window and ‘X-GNOME-Autostart-enabled=true’ to ensure the file runs at every login.
Bypassing Security Measures
Because .desktop files on Linux are typically text-based and their abuse is not widely documented, security tools are unlikely to monitor them as potential threats. This allows the attackers to bypass customary security measures.
The payload dropped by the malformed .desktop file is a Go-based ELF executable designed for espionage. It can remain hidden or establish persistence using cron jobs and systemd services. Interaction with the command-and-control (C2) server is facilitated through a bi-directional WebSocket channel, enabling data exfiltration and remote command execution.
A growing Threat
This campaign highlights the evolving threat landscape and the need for increased vigilance. As APT36 continues to refine its tactics, organizations must adopt proactive security measures to detect and prevent these types of attacks.
The use of .desktop files as a malware delivery mechanism is a concerning trend, as it exploits a lesser-known vulnerability in the Linux environment. Security professionals must educate users about the risks associated with opening suspicious files, even if they appear to be harmless documents.
The ongoing nature of these attacks underscores the importance of continuous monitoring and threat intelligence sharing. By working together, organizations can better protect themselves from the ever-evolving tactics of APT36 and other cyber espionage groups.
