logo

Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration

ID: 62694e20-3272-56a6-a4d5-691fd33853d2

STIX ID: report--62694e20-3272-56a6-a4d5-691fd33853d2

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Guru Baran

...
...

The article warns that attackers are increasingly abusing the legitimate PuTTY SSH client for covert lateral movement and data theft, sometimes using trojanized installers (delivering backdoors like Oyster) and exploiting PuTTY-related vulnerabilities (e.g., CVE-2024-31497). It identifies a reliable forensic artifact — SSH host keys recorded at HKCU\Software\SimonTatham\PuTTY\SshHostKeys — and recommends baselining PuTTY use, hunting registry keys, rotating SSH keys, whitelisting hosts, and monitoring anomalous SSH/exfiltration activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.