Suspicious XDG Autostart Desktop Entry Persistence via DISGOMOJI

PremiumReviewedSigma · Medium · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-05-13
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of a .desktop autostart entry under the user config autostart directory as used by DISGOMOJI malware for Linux persistence. The malware placed a desktop entry to relaunch itself at login. Autostart entries are a common Linux user-level persistence mechanism.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.