HomeSecurityWindows 10: malware download from background setup tool

Windows 10: malware download from background setup tool

The tool that adjusts the desktop image and lock screen can be used by hackers to install malware on a device.

malware

Malicious actors often use such binaries, known as living-off-the-land binaries (LoLBins), to perform illegal activities.

Through LoLBins, a hacker can download and install malware and avoid detection by a device's security (UAC or WDAC).

Cisco Talos released a list last year of 13 native Windows that can be used by attackers to download and execute malware:

  • powershell.exe
  • bitsadmin.exe
  • certutil.exe
  • psexec.exe
  • wmic.exe
  • mshta.exe
  • mofcomp.exe
  • cmstp.exe
  • windbg.exe
  • cdb.exe
  • msbuild.exe
  • csc.exe
  • regsvr32.exe

SentinelOne security researchers discovered that “ desktopimgdownldr.exe ”, located in the system32 folder of Windows 10, can also serve as LoLBin.

The executable is part of the Personalization CSP (configuration service provider) which allows, among other things, setting the lock screen and desktop background images.

Windows 10: malware download from background setup tool

Both for the desktop background and for the lock screen, the tool accepts JPG, JPEG, PNG files that are stored locally or remotely (supports HTTP/S URL addresses).

According to SentinelOne researcher Gal Kristal , running desktopimgdownldr.exe with administrator privileges overrides the user- lock screen image, resulting in a warning that something is wrong.

This can be avoided, however, if the attacker deletes the registry value immediately after executing the binary, without the user suspecting anything, and thus being able to proceed with the execution of the malware.

Kristal found that while the executable appears to require elevated privileges so that it can create files in C:\Windows and the registry, it can also be run with the privileges of a standard user, to download files from an external source.

Kristal says, however, that a user could fix the situation. He suggests that those using Endpoint Detection and Response add “desktopimgdownldr.exe” to their watchlists so they can detect and deal with it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS