logo

Ssh… Don’t Tell Them I Am Not HTTPS: How Attackers Use SSH.exe as a Backdoor Into Your Network

ID: bedf7404-ab3c-5309-abc9-ec19e27b8b06

STIX ID: report--bedf7404-ab3c-5309-abc9-ec19e27b8b06

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2023-03-21

Date Updated: 2026-04-27

Author: BHIS

...
...

This BHIS incident report describes attackers abusing Windows OpenSSH to establish reverse SSH tunnels (using flags like -f -N -R and StrictHostKeyChecking=no) from compromised servers into an external host, persisted via a scheduled task and a specially configured tunnel-only user with an empty password; the tunnels were used to proxy RDP and enable further access. The report highlights detection opportunities (egress filtering, application-layer firewalling, alerts for unusual SSH flags and suspicious known_hosts entries) and notes this technique is not widely documented in ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.