216.73.217.22

Chinese Hackers Attacking Linux Devices With New SSH Backdoor

· Published 05/02/2025 22:05 · Modified 05/02/2025 22:18

Export JSON

Essential information

Published
05/02/2025 22:05
Modified
05/02/2025 22:18
Tags
2025-02-05 c2 server iot linux lunar peek campaign network appliances ssh backdoor
Related entities
3 observables, 1 intrusion sets (apt), 12 techniques (mitre)

Description

Chinese hackers, specifically the DaggerFly espionage group, are targeting devices with a sophisticated called ELF/Sshdinjector.A!tr. The , active since mid-November 2024, primarily focuses on and devices. The attack involves a dropper that deploys malicious binaries, including a modified SSH library and infected versions of common utilities. The core backdoor communicates with a remote , enabling system information gathering, data exfiltration, and arbitrary command execution. The malware uses a custom communication protocol with hardcoded identifiers and can perform various actions through specific command IDs. Users are advised to keep their AntiVirus definitions up-to-date to mitigate the threat.

External references