logo

APT36 hackers abuse Linux .desktop files to install malware in new attacks

ID: fae20b6a-c625-5932-a399-6567dab63505

STIX ID: report--fae20b6a-c625-5932-a399-6567dab63505

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-08-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT36 is running an active espionage campaign against Indian government and defense targets by abusing Linux .desktop files delivered in phishing ZIPs; the malicious .desktop entries run shell commands to fetch and write a hex-encoded Go-based ELF payload to /tmp, make it executable, launch it (while opening a decoy PDF), and establish persistence (autostart, cron, systemd) and bi-directional WebSocket C2 for data exfiltration and remote control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.