ATT&CKReferencesESET ForSSHe December 2018

ESET ForSSHe December 2018

Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupWindigo

Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.

T1016
System Network Configuration Discovery
MalwareKessel

Kessel has collected the DNS address of the infected host.

T1016
System Network Configuration Discovery
MalwareBonadan

Bonadan can find the external IP address of the infected host.

T1027.013
Encrypted/Encoded File
MalwareKessel

Kessel's configuration is hardcoded and RC4 encrypted within the binary.

T1030
Data Transfer Size Limits
MalwareKessel

Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries.

T1033
System Owner/User Discovery
MalwareBonadan

Bonadan has discovered the username of the user running the backdoor.

T1041
Exfiltration Over C2 Channel
MalwareKessel

Kessel has exfiltrated information gathered from the infected system to the C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKessel

Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS.

T1057
Process Discovery
MalwareBonadan

Bonadan can use the ps command to discover other cryptocurrency miners active on the system.

T1059
Command and Scripting Interpreter
GroupWindigo

Windigo has used a Perl script for information gathering.

T1059
Command and Scripting Interpreter
MalwareBonadan

Bonadan can create bind and reverse shells on the infected system.

T1059
Command and Scripting Interpreter
MalwareKessel

Kessel can create a reverse shell between the infected host and a specified system.

T1082
System Information Discovery
MalwareKessel

Kessel has collected the system architecture, OS version, and MAC address information.

T1082
System Information Discovery
MalwareBonadan

Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on.

T1082
System Information Discovery
GroupWindigo

Windigo has used a script to detect which Linux distribution and version is currently installed on the system.

T1083
File and Directory Discovery
GroupWindigo

Windigo has used a script to check for the presence of files created by OpenSSH backdoors.

T1090
Proxy
MalwareKessel

Kessel can use a proxy during exfiltration if set in the configuration.

T1105
Ingress Tool Transfer
MalwareBonadan

Bonadan can download additional modules from the C2 server.

T1105
Ingress Tool Transfer
MalwareKessel

Kessel can download additional modules from the C2 server.

T1132.001
Standard Encoding
MalwareKessel

Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries.

T1140
Deobfuscate/Decode Files or Information
MalwareKessel

Kessel has decrypted the binary's configuration once the main function was launched.

T1496.001
Compute Hijacking
MalwareBonadan

Bonadan can download an additional module which has a cryptocurrency mining extension.

T1518
Software Discovery
GroupWindigo

Windigo has used a script to detect installed software on targeted systems.

T1554
Compromise Host Software Binary
MalwareKessel

Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1554
Compromise Host Software Binary
MalwareBonadan

Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1556
Modify Authentication Process
MalwareKessel

Kessel has trojanized the <sode>ssh_login</code> and user-auth_pubkey functions to steal plaintext credentials.

T1560
Archive Collected Data
MalwareKessel

Kessel can RC4-encrypt credentials before sending to the C2.

T1573.001
Symmetric Cryptography
MalwareBonadan

Bonadan can XOR-encrypt C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.