Researchers reported that Windows Subsystem for Linux 2 (WSL2) can be abused to stage malware payloads while evading much of the visibility provided by Windows-native telemetry. Unlike WSL1, which maps Linux activity into the Windows process model, WSL2 runs a full Linux kernel inside a lightweight Hyper-V VM with its own process space, filesystem, and network stack. As a result, network activity initiated inside WSL2 may not appear in Windows tools such as Sysmon, creating a gap for defenders trying to reconstruct attacker behavior.
The reporting shows that when a process inside WSL2 writes files into the Windows filesystem through /mnt/c/, the resulting activity is attributed on the Windows side to DllHost.exe via the Plan 9 (9P) proxy layer and vp9fs.dll, rather than to the originating Linux process. That split obscures the attack chain and turns payload staging into an indirect execution problem, although launching Windows binaries from WSL remains visible because normal Windows processes are created with wsl.exe as the parent. Defenders were advised to use outcome-based detections, including monitoring for unexpected wsl.exe execution and suspicious DllHost.exe creation of executable or script files in user-writable paths such as Users\Public, ProgramData, and Windows\Temp.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
An article described how WSL2 can be abused for payload staging in ways that evade normal Windows-native telemetry, including network activity invisible to Sysmon and Windows file writes attributed to DllHost.exe via the 9P layer. The write-up also discussed defender-visible artifacts and proposed outcome-based detection, including a Sigma rule for suspicious DllHost.exe file creation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.