22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
ID: f69df578-a1f7-5e70-926c-67e146da296f
STIX ID: report--f69df578-a1f7-5e70-926c-67e146da296f
Feed Name: SANS ISC Diary
Threat Score
On May 23, 2026 a Cowrie SSH honeypot captured an automated credential-stuffing campaign (mdrfckr) that, within 22 seconds of a successful login, injected an SSH backdoor key, changed the root password, and removed host-based restrictions; the report provides IOCs (163.7.8.79, root/Aa123123123, SSH key hash), cross-references to threat-intel sources, MITRE ATT&CK mappings, and concrete mitigations (disable password auth, enforce strong passwords, rate-limit/lockout, monitor logs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
