Suspicious FireWood Autostart Desktop Entry gnome-control Creation via File System

PremiumReviewedSigma · High · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of an autostart desktop entry named gnome-control.desktop, the persistence mechanism of the FireWood backdoor associated with the WolfsBane intrusion set. The name imitates the GNOME Control Center to appear legitimate while relaunching the implant at login. This indicates XDG autostart persistence on a compromised Linux desktop.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.