logo

Weaponized Military Documents Deliver Advanced SSH-Tor Backdoor

ID: a1de58c3-854f-5e79-b39b-a45c2b29f4f6

STIX ID: report--a1de58c3-854f-5e79-b39b-a45c2b29f4f6

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2026-06-09

Date Updated: 2026-07-17

...
...

CRIL identified an October 2025 espionage campaign distributing a weaponized ZIP disguised as a Belarusian military PDF that uses an LNK-triggered PowerShell chain, anti-sandbox checks, and scheduled tasks to deploy OpenSSH for Windows and a customized Tor hidden service with obfs4 bridging; the infrastructure exposes SSH, RDP, SFTP and SMB over .onion addresses using pre-generated RSA keys, enabling anonymous remote access. The report includes technical analysis, MITRE TTP mapping, indicators (file hashes and an .onion), mitigation recommendations, and assesses moderate confidence in similarities to Sandworm (APT44) while noting no secondary payloads were observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.