WSL — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
October 29, 2025
Last Seen
November 16, 2025

Related Threat Clusters

  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • Qilin Ransomware Uses WSL to Deploy Linux Encryptors on Windows Systems

    Qilin ransomware has been identified using Windows Subsystem for Linux (WSL) to execute Linux encryptors on Windows systems. This method allows attackers to bypass traditional Windows defenses by running ELF binaries,…

    2 articles · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Cyberespionage

    The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…

    1 article · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…

    4 articles · Updated November 5, 2025
  • Qilin Ransomware Uses WSL to Run Linux Encryptors on Windows

    Qilin ransomware has been identified using Windows Subsystem for Linux (WSL) to execute Linux encryptors on Windows systems, allowing attackers to bypass traditional Windows defenses. The malware operates by executing…

    2 articles · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…

    5 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Microsoft November Patch fixes critical Zero-Day flaw — Bangkokpost · November 16, 2025
  • Russian APT abuses Windows Hyper — Csoonline · November 5, 2025
  • Russian hackers abuse Hyper — Bleepingcomputer · November 4, 2025
  • Ransomware hackers are now running Linux encryptors in Windows to stay undetected — Techradar · October 29, 2025

CVSS v3.1 Breakdown