logo

XZ backdoor: Hook analysis

ID: 21eee0ff-aa2d-5ef6-933b-adae16b2ed4f

STIX ID: report--21eee0ff-aa2d-5ef6-933b-adae16b2ed4f

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2024-06-24

Date Updated: 2026-04-29

Author: Anderson Leite, Sergey Belov

...
...

Kaspersky's Part 3 analysis of the XZ backdoor describes a highly sophisticated OpenSSH backdoor that embeds an encrypted ED448 public key via code-level steganography, hooks RSA/OpenSSH authentication flows to allow arbitrary logins and fake-key authentication, supports remote command execution (including root-mode operations), and hides evidence by filtering syslog messages and replacing logged keys; the report includes anti-replay protections and provides vendor detection names (HEUR:Trojan.Script.XZ, Trojan.Shell.XZ, MEM:Trojan.Linux.XZ).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.