HomeSecurityChinese cyberspies use new SSH backdoor

Chinese cyberspies use new SSH backdoor

A Chinese hacking group is exploiting the SSH daemon on networked devices through a new malicious backdoor, securing permanent access and the ability to perform hidden actions.

See also: Chinese hackers MirrorFace have been attacking Japan since 2019

SSH backdoor

The newly identified attack suite has been actively used since mid-November 2024, by the Chinese cyberespionage group Evasive Panda, also known as DaggerFly.

According to findings by Fortiguard , the attack suite is called “ELF/Sshdinjector.A!tr” and consists of malware injected into the SSH daemon to perform a wide range of actions. Fortiguard says that ELF/Sshdinjector.A!tr has been used in attacks against network devices, but while it has been documented in the past, there are no detailed reports on how it works.

The Evasive Panda group has been active since 2012 and recently came to the fore for attacks deploying a new macOS backdoor, carrying out supply chain attacks via ISPs in Asia, and harvesting information from US organizations in a four-month operation.

See also: Over 4,000 backdoors seized via expired domains

While Fortiguard has not disclosed how network devices are initially compromised, once compromised, a dropper component checks to see if the device is already infected and if it is running with root privileges.

Chinese cyberspies use new SSH backdoor

If the conditions are met, several binaries, including an SSH library (libssdh.so), will be dropped on the target machine. This file acts as the main backdoor component, responsible for command and control (C2) communications and data extraction.

Other binaries, such as “mainpasteheader” and “selfrecoverheader,” help attackers ensure persistence on infected devices. The malicious SSH backdoor is injected into the SSH daemon and then waits for incoming commands from the C2 to perform system reconnaissance, credential theft, process monitoring, remote command execution, and file manipulation.

Fortiguard also noted that it used AI tools to reverse engineer and analyze this malware. While this was not a simple process, the tool showed promising potential.

See also: Cloud Atlas hackers use Microsoft Office vulnerability to distribute backdoors

Backdoors, such as the one affecting the SSH daemon, are unauthorized access points that are intentionally or maliciously created within systems to bypass authentication mechanisms. They exploit vulnerabilities in Secure Shell protocols, allowing attackers to gain remote access, monitor, or control targeted servers without detection. These backdoors are often installed through malware, system misconfigurations, or even insider threats. To mitigate such risks, it is essential to implement strong security practices, such as regular updates, strong authentication methods, and continuous monitoring of system activities for anomalies. Prevention and early detection are crucial to protecting systems from potential backdoor exploitation.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS