XZ backdoor: Hook analysis
ID: 21eee0ff-aa2d-5ef6-933b-adae16b2ed4f
STIX ID: report--21eee0ff-aa2d-5ef6-933b-adae16b2ed4f
Feed Name: Securelist by Kaspersky
Kaspersky's Part 3 analysis of the XZ backdoor describes a highly sophisticated OpenSSH backdoor that embeds an encrypted ED448 public key via code-level steganography, hooks RSA/OpenSSH authentication flows to allow arbitrary logins and fake-key authentication, supports remote command execution (including root-mode operations), and hides evidence by filtering syslog messages and replacing logged keys; the report includes anti-replay protections and provides vendor detection names (HEUR:Trojan.Script.XZ, Trojan.Shell.XZ, MEM:Trojan.Linux.XZ).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
