Chinese cyberspies use new SSH backdoor in network device hacks
ID: 4cae0cd3-01fd-5b09-8d3f-1ab2b3ac7e4c
STIX ID: report--4cae0cd3-01fd-5b09-8d3f-1ab2b3ac7e4c
Feed Name: Bleeping Computer
FortiGuard researchers have documented ELF/Sshdinjector.A!tr, a malicious suite attributed to the Chinese APT Evasive Panda that injects a malicious SSH library into the SSH daemon of compromised network appliances to provide persistent backdoor access, credential theft, process monitoring, file transfer, remote shells, and other C2-driven actions; the report details the infection chain, 15 supported commands, persistence components, detection names, and VirusTotal sample hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
