Dropbear SSH is a lightweight Secure Shell implementation that has been repurposed by threat actors as a remote-access backdoor and persistence mechanism, particularly on embedded and resource-constrained systems. In intrusion activity affecting operational technology and critical infrastructure environments, actors have deployed Dropbear on victim modems or endpoints to maintain persistent remote access over SSH. Reported targeting includes internet-exposed industrial environments in sectors such as water and wastewater, energy, and government services and facilities, where attackers used legitimate engineering software to access programmable logic controllers and then established ongoing access through auxiliary network-connected devices.
Dropbear SSH has also been associated with Sandworm operations, including the 2015 Ukraine electric power attack, where a modified Dropbear SSH client was installed as a backdoor on target systems. In that context, reporting has described the use of a hardcoded backdoor password to preserve access within the victim network. These cases reflect use of Dropbear not as commodity administration software alone, but as an adversary-controlled remote access tool supporting persistence and post-compromise operations.
Because Dropbear is a legitimate SSH implementation commonly used on Linux and embedded devices, its malicious use can blend into expected administrative activity, complicating detection. In the observed OT-related intrusions, its role was to provide durable remote connectivity after initial compromise rather than to serve as the primary intrusion vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deployed Dropbear SSH on victim modems to maintain remote access over port 22.
During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems... Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks rely heavily on basic security failures. Threat actors have repeatedly exploited internet-facing programmable logic controllers (PLCs), weak or default passwords, shared operator accounts, poor IT/OT network segmentation, and exposed remote access tools.
The attacks rely heavily on basic security failures. Threat actors have repeatedly exploited internet-facing programmable logic controllers (PLCs), weak or default passwords, shared operator accounts, poor IT/OT network segmentation, and exposed remote access tools.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by actors on victim modems to maintain persistent remote access over SSH port 22.
Used by the actors to maintain remote access on victim cellular modems over SSH.
A modified Dropbear SSH client used as a backdoor for persistent remote access (including use of a hardcoded backdoor password).
A modified Dropbear SSH client was deployed as a backdoor/persistence mechanism, including use of a hardcoded backdoor password for continued access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.