This innocent Windows 10 feature could be used to mask malware attacks

(Image credit: Shutterstock / hywards)

Researchers have discovered a new living-off-the-land binary (LOLBin) in Windows 10 that could be exploited to conceal malware attacks.

Numerous LOLBins are present in Windows 10, all of which serve a legitimate function. However, with the right privileges, hackers can abuse these binaries to bypass security facilities and conduct attacks without alerting the victim.

The new LOLBin (desktopimgdownldr.exe) was discovered by security firm SentinelOne and is usually responsible for the innocuous task of setting custom desktop and lockscreen backgrounds.

Found in the Windows 10 system32 folder, the binary can reportedly be used as a “stealthy downloader” - an alternative to widely known LOLBin certutil.exe.

Windows 10 malware

According to the SentinelOne report, desktopimgdownldr.exe is deployed as part of Personalization CSP, which allows administrators to set and lock a user’s background image.

While the binary would traditionally override the existing desktop image (thereby notifying the user to its activation), a hacker could sidestep this red flag by deleting the registry immediately after running the binary. This way, a malicious file could be delivered onto the system undetected.

Although the binary is designed to be run by privileged users only, standard users can also abuse a particular function to run the LOLBin without administrator status.

Further, when triggered by a standard user, the executable fails to alter the background image (because the user lacks the necessary authorization), leaving behind no other artifacts than the downloaded file.

To mitigate against the threat posed, SentinelOne advises security professionals update their watchlists and treat the newly discovered LOLBin as they would the widely exploited alternative certutil.exe.

TechRadar Pro has asked the firm to clarify whether a non-business user is likely to be affected by an attack of this kind - and what they could to protect themselves.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Teams
Microsoft Teams is finally adding a tiny but crucial feature I honestly can't believe it never had
Apple Watch Ultra 2 move data
Apple is reportedly planning a huge future Apple Watch upgrade to turn it into an AI device with onboard cameras
Apple watch pair with iphone
The Apple Watch SE 3 is apparently in 'serious jeopardy', and the news isn't much better for the Ultra 3 or Series 11
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)