Kessel

S0487

Malware.View on attack.mitre.org

About this malware

Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot. Kessel has been active since its C2 domain began resolving in August 2018.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

Kessel has collected the DNS address of the infected host.

T1027.013
Encrypted/Encoded File

Kessel's configuration is hardcoded and RC4 encrypted within the binary.

T1030
Data Transfer Size Limits

Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries.

T1041
Exfiltration Over C2 Channel

Kessel has exfiltrated information gathered from the infected system to the C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS.

T1059
Command and Scripting Interpreter

Kessel can create a reverse shell between the infected host and a specified system.

T1082
System Information Discovery

Kessel has collected the system architecture, OS version, and MAC address information.

T1090
Proxy

Kessel can use a proxy during exfiltration if set in the configuration.

T1105
Ingress Tool Transfer

Kessel can download additional modules from the C2 server.

T1132.001
Standard Encoding

Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries.

T1140
Deobfuscate/Decode Files or Information

Kessel has decrypted the binary's configuration once the main function was launched.

T1554
Compromise Host Software Binary

Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1556
Modify Authentication Process

Kessel has trojanized the <sode>ssh_login</code> and user-auth_pubkey functions to steal plaintext credentials.

T1560
Archive Collected Data

Kessel can RC4-encrypt credentials before sending to the C2.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET ForSSHe December 2018 Open source
    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.