logo

SSHazam: Hide Your C2 Inside of SSH

ID: 4393dc66-73e8-5342-80e3-e36a9d78b8d7

STIX ID: report--4393dc66-73e8-5342-80e3-e36a9d78b8d7

Feed Name: Black Hills Infosec Blog

Date Published: 2019-01-08

Date Updated: 2026-04-27

Author: BHIS

...
...

The report outlines “SSHazam,” a technique for masking C2 traffic by running tools like PowerShell Empire through an SSH tunnel (optionally on port 443) to evade network detection, with instructions for key management, local/remote port forwarding, multi-stage redirectors via iptables, use of autossh to keep tunnels persistent, and optional Slack-based SSH login alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.