logo

Chinese cyberspies use new SSH backdoor in network device hacks

ID: 4cae0cd3-01fd-5b09-8d3f-1ab2b3ac7e4c

STIX ID: report--4cae0cd3-01fd-5b09-8d3f-1ab2b3ac7e4c

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-02-04

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

FortiGuard researchers have documented ELF/Sshdinjector.A!tr, a malicious suite attributed to the Chinese APT Evasive Panda that injects a malicious SSH library into the SSH daemon of compromised network appliances to provide persistent backdoor access, credential theft, process monitoring, file transfer, remote shells, and other C2-driven actions; the report details the infection chain, 15 supported commands, persistence components, detection names, and VirusTotal sample hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.