Bonadan is a Linux malware family built by maliciously modifying OpenSSH binaries to implant a backdoor on compromised systems. It is associated with trojanized OpenSSH server software used for covert persistence on internet-exposed Linux hosts. Bonadan has been documented as part of the broader ecosystem of Linux OpenSSH backdoors that provide stealthy access while also supporting credential interception opportunities inherent to tampered SSH components.
Bonadan supports remote shell access by creating bind and reverse shells on infected machines, enabling interactive post-compromise control. It can download additional modules from command-and-control infrastructure, indicating extensibility beyond its core backdoor functionality. The malware performs host reconnaissance by discovering the username under which it is running, identifying the external IP address of the infected host, and using process enumeration via the ps command to look for other cryptocurrency miners already active on the system. Its command-and-control communications can be obfuscated with XOR encryption.
Available reporting also links Bonadan to cryptocurrency-mining functionality, distinguishing it from OpenSSH backdoors focused solely on persistence and credential theft. The family targets Linux systems, especially servers where OpenSSH is commonly deployed and reachable from the internet. Infection vectors for trojanized OpenSSH malware families are often difficult to determine from malware samples alone, but such families are commonly associated with compromised SSH access, brute-force activity, or exploitation of exposed services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Bonadan can create bind and reverse shells on the infected system. gh0st RAT is able to open a remote shell to execute commands. Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that discovers the username of the user running it.
Finds the external IP address of infected hosts.
Discovers the username of the user running the backdoor.
Backdoor that identifies the external IP address of an infected host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.