Kessel is a Linux OpenSSH backdoor family built from trojanized OpenSSH binaries and associated with compromises of internet-exposed Linux servers. It modifies the OpenSSH binary on targeted systems to provide covert persistent access while also enabling credential theft, taking advantage of OpenSSH’s handling of authentication material. Kessel is one of the more feature-rich OpenSSH backdoor families documented in the wild and reflects the broader trend of SSH daemon backdooring for long-term server access.
Kessel supports multiple command-and-control and exfiltration channels, including HTTP, raw TCP, and DNS, and encrypts its communications with the command-and-control infrastructure. It can decrypt its embedded configuration at runtime, collect local network configuration details including the host’s DNS address information, and exfiltrate information gathered from the infected system. For DNS-based exfiltration, it can split stolen data into chunks sized to fit within DNS subdomains and encode that data in hexadecimal form. It can also send stolen credentials and other information via HTTP POST requests, TCP, and DNS, and can optionally use a proxy if configured.
Operationally, Kessel supports interactive post-compromise control through a reverse shell capability and can receive commands to upload or download files. Reported functionality includes RC4 encryption of credentials before transmission to command-and-control. The family is part of a wider ecosystem of Linux SSH backdoors in which initial compromise is often assessed to stem from stolen SSH credentials, brute-force activity, or exploitation of vulnerable exposed services, although specific infection vectors for individual samples are not always recoverable from malware analysis alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
Kessel stands out for its multiple methods of communicating with its C&C server. It implements HTTP, raw TCP and DNS.
Kessel stands out for its multiple methods of communicating with its C&C server. It implements HTTP, raw TCP and DNS.
Kessel stands out for its multiple methods of communicating with its C&C server. It implements HTTP, raw TCP and DNS.
AuditCred can utilize proxy for communications... FunnyDream can identify and use configured proxies in a compromised network for C2 communication... Kapeka can identify system proxy settings via WinHttpGetIEProxyConfigForCurrentUser() during initialization and utilize these settings for subsequent command and control operations... PoshC2 contains modules that allow for use of proxies in command and control.
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
AppleSeed has divided files if the size is 0x1000000 bytes or more. APT28 has split archived exfiltration files into chunks smaller than 1MB. APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.
ADVSTORESHELL exfiltrates data over the same channel used for C2.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collects DNS address information from infected hosts.
Malware that exfiltrates information gathered from infected systems to C2.
Backdoor that collects the DNS address of infected hosts.
Malware that decrypts its binary configuration after launch.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.