logo

Sandworm Uses SSH-over-Tor Tunnel for Stealthy Long-Term Persistence

ID: 19645fb1-61f9-55d8-a1d5-cc509bd63a0b

STIX ID: report--19645fb1-61f9-55d8-a1d5-cc509bd63a0b

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Mayura Kathir

...
...

This report describes a Sandworm (APT-C-13) campaign delivering malicious LNK files via spear-phishing ZIP attachments that execute PowerShell-based multi-stage payloads. The malware establishes persistence with scheduled tasks (masquerading as legitimate apps), deploys Tor hidden services and an SSH backdoor tunneled through Tor (SSH-over-Tor) to expose internal SMB/RDP services to operators, and uses obfs4, sandbox/VM checks, mutex controls and other evasion techniques; recommendations include monitoring scheduled-task creation, outbound Tor-like traffic, and restricting unauthorized SSH services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.