reverse_ssh is an open-source SSH-based reverse shell tool written in Go that is used to establish persistent remote access from compromised systems to attacker-controlled infrastructure. It has been observed deployed after successful exploitation of internet-exposed services, including VMware vCenter Syslog service compromise, where attackers used it alongside malicious scheduled-task or cron-based persistence to retain access. The tool periodically initiates outbound SSH connections, allowing operators to bypass some perimeter restrictions by relying on egress traffic rather than inbound access.
Its functionality supports reverse shell access, persistence of remote control channels, local and remote dynamic port forwarding, and file transfer through SSH mechanisms such as SCP and SFTP. These features make it useful for post-compromise operations including lateral movement, staging of additional tooling, and exfiltration of data. reverse_ssh has also been incorporated into other malware and backdoor operations, including Go-based tooling such as GoReShell associated with China-nexus intrusion activity.
Observed use spans multiple environments. In 2026 exploitation of VMware vCenter vulnerabilities, attackers deployed reverse_ssh on compromised appliances to maintain persistent access after remote code execution. Separately, Linux payloads delivered through a malicious npm supply-chain campaign were identified as clients of the reverse_ssh project, showing its reuse as a commodity post-exploitation component. The tool itself is not inherently tied to a single threat actor, but its presence on enterprise infrastructure is a strong indicator of compromise because it is commonly used to maintain covert remote access after initial intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that could be exploited by an unauthenticated attacker with network access to execute arbitrary code.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
The threat actor behind the operation also relied extensively on cron to execute malicious payloads, including to fetch and run a shell script ("esxi.sh") from the IP address "185.144.28[.]120:3232."
... dass die bösartigen Akteure sich mittels der „reverse_ssh“ in die Systeme eingenistet haben, einem quelloffenen SSH-basierten Reverse-Shell-Framework.
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
The threat actor behind the operation also relied extensively on cron to execute malicious payloads, including to fetch and run a shell script ("esxi.sh") from the IP address "185.144.28[.]120:3232."
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
Quirso, said a threat actor has been exploiting CVE-2026-59310 and using reverse secure shell (SSH) to maintain access to compromised systems... Quirso’s reported attack chain used a cron job (time-based task scheduler) and reverse_ssh to create an outbound connection to attacker infrastructure.
The linuxFile implant is designed to provide remote command execution capabilities to the attacker. It establishes a connection to its controller over a WebSocket channel to receive instructions
The reverse SSH connection provides an outbound command-and-control (C2) channel and can also help bypass firewalls or other network security measures.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used via a malicious cron job to provide persistent reverse SSH access on compromised VMware vCenter systems after exploitation of CVE-2026-59310.
An SSH-based reverse-shell tool used post-exploitation to establish persistent backdoor access, maintain outbound connect-backs, enable port forwarding for lateral movement, and support SCP/SFTP file transfer and exfiltration.
Open-source Golang reverse shell client deployed on Linux as part of the ambar-src infection chain, enabling remote interactive access/pivoting from compromised developer hosts.
Open-source tool providing reverse SSH capability; its functionality is leveraged by GoReShell to create attacker-controlled reverse SSH access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.