logo

Attackers Abuse WSL2 to Operate Undetected on Windows Systems

ID: c59b4613-37e8-5462-aa82-5bb35688a32f

STIX ID: report--c59b4613-37e8-5462-aa82-5bb35688a32f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes how WSL2 can be abused as a stealthy enclave for attackers: researchers built a Cobalt Strike BOF that uses the WSL COM interface to enumerate WSL2 instances and execute Linux processes without spawning wsl.exe, avoiding common EDR detections. It details versioning and COM marshalling challenges, the use of dynamic IDL reconstruction to support multiple WSL releases, real-world abuse implications (access to unmonitored files, SSH keys, credentials, and internal networks), and recommends treating WSL2 as part of the enterprise attack surface (monitor wsl.exe usage, inspect WSL filesystems, and watch for suspicious COM activity).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.