Dropbear SSH is legitimate Secure Shell software that threat actors have deployed or modified to provide persistent remote access to compromised systems. Its malicious use includes a backdoored implementation with a hardcoded password, enabling attackers to retain access within victim networks. The legitimate software is not inherently malware.
Sandworm Team installed a modified Dropbear SSH implementation as a backdoor during the 2015 Ukraine electric power attack and has used a hardcoded backdoor password to maintain network persistence. Iranian-affiliated actors have also deployed Dropbear SSH on compromised endpoints, including modems, to preserve remote access during campaigns targeting U.S. operational technology environments. Those campaigns affected government services, water and wastewater systems, and energy infrastructure. In these operations, Dropbear served as a remote-access and persistence tool; manipulation of industrial controller logic and operational displays was performed through other tools and should not be attributed to Dropbear itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network.
Deployed Dropbear SSH on victim modems to maintain remote access over port 22.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by actors on victim modems to maintain persistent remote access over SSH port 22.
Used by the actors to maintain remote access on victim cellular modems over SSH.
A weaponized instance of legitimate SSH software containing a hardcoded backdoor password, used by Sandworm Team to maintain network persistence.
A backdoored deployment of the legitimate Dropbear SSH software, using a hardcoded password to maintain network persistence. This characterization applies to the deployment described, not to ordinary Dropbear SSH installations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.