Bonum Certa Men Certa

WSL Windows Malware Steals Browser Cookies, Deploys Remote Access Trojan

Guest post by Ryan, reprinted with permission from the original

WSL Windows malware steals browser cookies, deploys Remote Access Trojan.



Microsoft has spent a lot of time and money trying to Embrace, Extend, and Exterminate GNU/Linux. First, they decried it a cancer and Communism.



Then they released seed money for a failing company called SCO to raise all kinds of hell with vexatious litigation, which was the subject of an entire blog following the incident for many years, called Groklaw.



Then they realized that the reason professionals don’t like Windows is that it’s not very technically sound and isn’t powerful enough to actually use for many important tasks.



In fact, even more than a decade ago when I was making my own custom Linux kernels to use on top of Ubuntu, the default number of processors supported by their kernel was 512, and in Windows today, although it supports more than 64 processors today, it becomes such a scheduling disaster, that if you need to run such a system, you probably don’t want to use Windows.



I pared down the Linux kernel because I was just using it on my quad core PC and backporting some graphics code and stuff.



The fundamental reasoning behind the Windows Subsystem for Linux is deeply flawed and shows that Microsoft fundamentally misunderstands the problem that they claim it solves, and maybe they’ve just lost their marbles and don’t realize what decade this is and that they can’t keep trotting out the obsolete Windows battlewagon that’s had its day and isn’t looking so good.



They’ve even lost Paul Thurrott, whose sole income appears to be praising Microsoft on his blog. He’s been writing articles on everything from bashing how pushy their browser Edge is to pointing out what a dog their developer kit for their latest half-assed ARM transition is.



Seriously, they’re trying this again, and it’s barely powerful enough to overcome Windows and run at all (you can look at what people are saying about it running slowly all over the place….too many to list here), so I suppose you can basically forget about x86 software. Some splogs promise Windows on ARM will be “different this time”, but Microsoft seems to be screwing it up the exact same way Windows RT went.



Nobody wanted them because they were wimpy on the specs and didn’t have a strong showing of compatible software.



But back to WSL. Why would anyone use it?



Well, Microsoft’s original botched attempt (retconned as WSL1) was essentially to pay some clowns they have to write a crappy Microsoft approximation of a Linux kernel without really understanding how the Linux kernel worked, and that went as well as it sounds.



So they started over and redid “WSL2” as a real Linux kernel (and a very old one, at that) running on their Hyper-V system. And so it’s basically a virtual machine with integration into the host.



The upsides are that it performs a bit better (but nowhere near as well as GNU/Linux operating systems running natively on the hardware in question) and is more compatible.



The downside is, well, when you implement a “Linux” VM on top of Windows, you don’t give Windows the strengths of “Linux”.



You make a “Linux” system that has the failings of Windows. Namely, that Windows has lousy performance on just about any computer and is absolutely overflowing with malware.



Microsoft is also taking the opportunity to “extend” “Linux” so that applications can use Windows-only technologies that are NOT Linux-compatible.



In this way, it’s basically a rehash of the Microsoft “Java” VM, where they gutted it of all of the cross-platform JAVA stuff and shoved in things that only worked on Windows. But they’ve sharpened their knives a little and they’re doing it in a way where people will not sue them this time.



Whether they comply with the software licenses or not is, at this point, irrelevant, in many cases, because they’ve bought off the foundations that manage major open source infrastructure (and in some cases, rather cheaply. Less than $50,000 got them the Raspberry Pi Foundation cramming Microsoft programs into your Pi…..).



You can’t kill the devil while he’s the one that’s paying the bills.



Microsoft knows this.



So WSL and Influence Peddling are just Phase III of their attack on open source software. This time they say they’re going to “kill us with kindness”. But the emphasis should be on the killing part. Broadly, I group their previous two attempts as trying to pretend it doesn’t exist with the occasional bucket ‘o FUD (Phase I) and then seeding SCO’s meritless lawsuits with a $20 million bailout to a bankrupt company for a “Unixware” license they almost certainly didn’t use anywhere. (Phase II)



Although WSL is a massive new liability for Windows users, as all of these WSL viruses are coming around, Microsoft is trying to “make hay while the sun is shining” from the fact that they’ve added attack surface to their own OS and created a new security nightmare for their own customers, by painting WSL malware as “Linux” and “open source”.



I’ve been using GNU/Linux regularly since Vista came out and chased me away from Windows, but longer than that, and I’ve always felt creeped out when I was running Windows, mainly because there’s so much malware, and not much security other than lip service and theater, and the fact that “SmartScreen” and “Defender”, and “Telemetry” are built-in malware and keyloggers, but I have not felt creeped out when I was running GNU/Linux.



Most of the security problems facing Windows users simply do not affect GNU/Linux unless the user goes through some great effort to install malware through some actions that are both unwise and cautioned against, and as for the “you wake up and it’s just there and all your files are encrypted” issues with Windows, which keep occurring, that also tends not to happen to GNU/Linux for a multitude of reasons.



I’d imagine the fact that there’s 10 times less code in a fully functional GNU/Linux OS, which even comes complete with a freaking office suite that isn’t some idiotic trialware has something to do with that, but it’s also that it’s well documented that open source software has less bugs in general and patches roll out to the users for the critical stuff a lot faster too, and the official package managers check to see that the software you want isn’t tampered with or corrupt, before they install it.



And with Windows, a lot of people go and brick the update system (on purpose) because they never know what broken updates are coming down the pipe, or if their computer will even reboot when it gets done installing them. It happens so often that every month there’s articles about Microsoft pulling back broken updates, in addition to the usual security mess.



Why would anyone trust this company to do something like WSL?



In closing, I’d like to thank Bleeping Computer for calling out Windows and WSL in this. It’s something that just doesn’t happen that often because Microsoft pays “journalists” good money to not have their products and their company associated with the problems they create.



The particular RAT malware that this article talks about displays a pop-up eventually, in Turkish, on the Windows desktop, which translates to “you’re screwed and there’s not much you can do.”.



Well, I hope you have backups.



You can recover from them while you’re installing a different operating system. And then it shouldn’t happen again.



You can do something about this malware today.



You can switch to a robust operating system that is hardened against these kinds of attacks.



But none of those operating systems are from Microsoft.



Windows on ARM is some sort of pipe dream that someone at Microsoft keeps having.



“Wouldn’t it be nice if we could start over on hardware that’s not a complete disaster and get good power efficiency, and not be tied down by this legacy crap?”.



Nice for them maybe, but once you detach Windows from legacy software, there’s no longer any point in running it, and Intel is an inseparable part of that legacy.



The problem for Microsoft is that users are voting with their feet and leaving in droves. Everyone from Statcounter to Pornhub can tell you that.



Calling Windows the future of operating systems is like calling Sears the future of retail.



Recent Techrights' Posts

"Cloud Computing" Was Always a Joke, But This Week Was the Punchline
Maybe stop following tech trends and fashions
A radical proposal to keep your personal data safe, by Richard Stallman
"The surveillance imposed on us today is worse than in the Soviet Union. We need laws to stop this data being collected in the first place"
 
Who Asked Software in the Public Interest (SPI) for a Refund? ($100,000, Resulting in Losses of $267,201 in 12 Months, Highest-Ever Losses)
The IRS does not reveal who or what's tied to this refund (or the cause/reason)
Trouble in Red Hat/IBM and a Retreat to Ponzi Economics in Search of Wall Street Market Heist
Would you invest your life savings in this kind of crap?
12 Months Ago the 'Hulk Hogan of UEFI' Officially Went 'Tag-Team'
We're actually sort of flattered or proud that such despicable people are so desperate to censor us
"Cloud Computing" Does Not Mean Safety
Fault tolerance is related to the notion of software freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 21, 2025
IRC logs for Tuesday, October 21, 2025
The Fall of Windows: From Something to Nothing
Of course Microsoft will pretend everything is fine and "just trust the hey hi" (AI)
Sounds Like Fedora is Ready to Become Less of a Slave of Microsoft (GitHub)
This seems like a belated move in a positive direction
XBox is a Dead Microsoft Product in a Dying Industry
It's probable that another wave of XBox layoffs is just over the horizon (maybe even before month's end)
Progress on Techrights Site Search
Fun times
IBM's Bluewashing of Red Hat Means the Layoffs Are Silent, Barely Reported
Don't wait to hear about "Red Hat layoffs"
Gemini Links 21/10/2025: Happy Disconnection, AWS Falling Apart, Closing of Gemlog Blue
Links for the day
Full Audio of Today's Richard Stallman Talk in the Technical University of Munich
Free/Libre software and freedom in the digital society
Microsoft XBox is Just Vapourware (Promises of Hardware That Doesn't Exist), Real Products Perish
just as developers lose interest in developing for XBox Microsoft is increasing the costs imposed upon them
Slopwatch: Fake Articles (Slop) in "Linux" Clothing in Google News (Noise)
all about what Google does
Links 21/10/2025: Even "Inventor of Vibe Coding" Rejects Vibe Coding, USPTO Experiments With Slop in Examination
Links for the day
Richard Stallman Talk Now Available for Viewing (Archived Copy, Not Live-streamed)
This recording is over 2 hours old
Links 21/10/2025: AWS-Induced Chaos and Social Control Media Curbs
Links for the day
Gemini Links 21/10/2025: Programming, StarGrid, Brand-New Palm OS Strategy Game in 2025, and Chatbot as Addiction Mechanisms
Links for the day
The African Lion and the American Cowards
Safaris exist for people to watch and enjoy animals
Amazon Web Shenanigans Perfectly Timed for Today's Talk by Richard Stallman
Maybe listen to him instead of looking for excuses to ridicule the messenger
Mission:Libre Has Taken Off (Project by Carmen Maris)
there will be a lot more to report on next month (after the event)
Techrights to Publish More EPO Leaks Next Week
We're meanwhile also doing lots of work on search, whose interface now looks better
Links 21/10/2025: 'The Lost Art' of Neon Signs and Twitter (X) to Enable Identity Theft (or Handle Theft) as a Service
Links for the day
Plagiarism With LLM Slop: Hindustan Times (HT Digital Streams Limited) Has Become a Slop Factory/Hub
What a disgrace
Next Week We Launch Search at Techrights
We're planning to launch it some time next week. Maybe Tuesday, maybe Thursday.
Talk by Richard Stallman Will be Live-streamed in Less Than 10 Hours
Happy hacking
"No Kings" in the Software World (GAFAM Should Not Exist, Either)
"No Kings" is a good slogan. Let's start by ridding ourselves of masters, not only those who reside in DC or visit DC
Every Morning
Bugs/edge cases combined with automation can spell disaster
Insane, Deliberately Dishonest, or Just Another Bigot?
very intellectually-dishonest human being
A Lot of Techrights is Built on Perl
Perl also runs the sister site
The Register MS Selling Slop for Microsoft (Vapourware, Ponzi Scheme, False Claims)
What will be left of The Register MS if it keeps repeating falsehoods and looking to profit from Ponzi schemes?
analytics.usa.gov Says Less Than 14% of Web Requests (to Government Sites) Come From Vista 11
Vista 11 was released more than 4 years ago!
People Who Attempt to Take Down Correct Information Need a Doctor a Day
“Journalism is printing something that someone does not want printed. Everything else is public relations.” ― George Orwell
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 20, 2025
IRC logs for Monday, October 20, 2025
Vista 11 is Sinking While Microsoft is PIPing (Mass Layoffs But Silent Layoffs)
We're witnessing a shift in platform dominance
Richard Stallman is Having a Good Week Already (Stallman Was Right About 'Clown Computing')
That alone is worth bringing up in his talk
An Update About Soylent News, With Jan Rinok "Back in the Saddle"
Burnout or "near burnout" a possibility when having to curate abuse
When Prominent GNU/Linux Distros Are Run by Spies
What has Microsoft Canonical become?
More Publishers and Companies Nowadays Say "GNU/Linux", Not "Linux"
It's not to see InstallAware saying GNU/Linux this week
Google News is Now Promoting a Parasitic Slopfarm Called "findarticles.com", Where Plagiarism of "Linux" Articles is Rampant
Does Google even care about the slop epidemic? Google itself is a vendor of slop now (and it calls it "Gemini")
Gemini Links 20/10/2025: Pumpkin Carving, "Hey Hi", and Other Buzzwords
Links for the day
Slopwatch: Google News Promoting Fear, Uncertainty, Doubt (FUD)
What is the value of Google News if so many results in it are fake 'articles?
Rejecting 'Snoop-Phones' and Turning "Old" Phones (or Tablets) Into Freedom-Respecting Appliances
Paul Fernhout (pdfernhout.net) wrote back to Akira Urushibatathis this past weekend
Our Uptime This Year Was Better Than AWS (Also a Lot Cheaper)
We never used "the cloud"
Amazon Web Shenanigans
An ongoing, experimental endeavour
Death of Elias Diem: FSFE mailing list archives hidden
Reprinted with permission from Daniel Pocock
Links 20/10/2025: Louvre Museum Reveals Weakness, About 7 Million Protest US Turning Into Oligarchy/Monarchy
Links for the day
They Should Have Listened to Techrights Over a Month Earlier (Xubuntu Site Compromised)
we reported this issue about 40 days earlier and nobody did anything about it
Richard Stallman to Give Another Talk Today in Bavaria (Bavarian Academy of Science)
Tomorrow at 6 PM he speaks in Munich
Apple is the Company of Dictators and Worse
Apple is just another greedy corporation in search of sweatshops and even pedophiles (especially the high-profile ones)
Counting Unhatched Eggs Is Not Counting Chickens
Everything here will persist as normal
Barry Kauler Explains That Puppy Linux and EasyOS Exclude Systemd to Keep Things Simple
Barry Kauler's Puppy Linux is in the community's hands. He now focuses on EasyOS and more.
The "Infinite Bread"
The biblical story of Jesus feeding the 5,000 has software parallels
Half a Year After Brian Fagioli Got Kicked Out of BetaNews for Slop He's Still Doing LLM Slop and Slop Images Targeting 'Linux' (Plagiarising Original Works)
If the Web gets polluted or flooded by slopfarms such as these, and Slashdot then sends traffic so these slopfarms (Slashdot probably doesn't do this intentionally), then real writers with real knowledge of GNU/Linux will lose the spark for publishing
In Many Cases and in Many Different Ways, Technology Became Less Durable and Less Reliable Over Time
The "modern" things are more complex. And complexity is a foe or reliability and repair-ability.
Microsoft's LinkedIn is Losing Money, Traffic, and Hope; Now It Wants to Sell Its Users' Lifeblood (and Data)
Let this be a reminder of what social control media really is about
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, October 19, 2025
IRC logs for Sunday, October 19, 2025
Campaign of FUD Against Framework Laptops and GNU/Linux (Using Microsoft's Attack on Linux, 'Secure Boot')
Ritual Defamation Cult has turned its attention over to Framework
Microsoft Lunduke: Freedom of Speech Means Spreading What I Have to Say and Banning People I Disagree With
4Chan is one he aims for and he is siccing 4Chan trolls at people he doesn't like
Liberation From 'The Feed'
They rank things based on the editor's choice/ideology (he or she knows the sponsors, hence the masters)
Microsoft's Killing of Vista 10 Seems to Have Resulted in More Articles About GNU/Linux (But Also FUD)
We not only saw a rise in traffic, we also saw a remarkable rise in the number of articles