Actionable threat hunting with Threat Intelligence (I) - Hunting malicious desktop files
Essential information
- Published
- 16/05/2025 08:22
- Modified
- 21/05/2025 20:43
- Tags
- 2025-05-16 desktop files gnome google drive google threat intelligence kde linux obfuscation pdf threat hunting xfce
- Related entities
- 3 observables, 7 techniques (mitre), 3 others
Description
This analysis explores the detection of malicious .desktop files used by threat actors to infect Linux systems. It explains the structure of these files and how they are manipulated to obfuscate malicious content. The report details the execution process of these files, which often involve opening PDF files from Google Drive as a distraction while downloading malware. Various threat hunting techniques are presented, including searching for specific processes, command lines, and file contents. The article provides several Google Threat Intelligence queries for identifying suspicious .desktop files and related malicious activities. It also includes a list of recently discovered samples potentially linked to a campaign reported by Zscaler.