Weaponized Military Documents Deliver Advanced SSH-Tor Backdoor
Essential information
- Published
- 05/11/2025 12:36
- Modified
- 05/11/2025 21:51
- Tags
- 2025-11-05 belarusian air force defense sector military lure obfs4 openssh ssh-tor backdoor tor hidden service uav operations
- Related entities
- 1 intrusion sets (apt), 12 techniques (mitre), 2 others
Description
A sophisticated cyber attack targeting the defense sector was identified in October 2025, utilizing a weaponized ZIP archive disguised as a military document. The multi-stage attack employs advanced evasion techniques and deploys a complex infrastructure combining OpenSSH for Windows with a customized Tor hidden service. The malware establishes persistent backdoor access, allowing anonymous remote access via SSH, RDP, SFTP, and SMB protocols. The lure document targets Belarusian Air Force drone experts, suggesting intelligence gathering on regional UAV capabilities. The attack's tactics, techniques, and procedures align with those of Sandworm (APT44), a Russian-linked APT group, although definitive attribution remains uncertain at this stage.