SSH

T1021.004

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.

SSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user enables it. On ESXi, SSH can be enabled either directly on the host (e.g., via `vim-cmd hostsvc/enable_ssh`) or via vCenter. The SSH server can be configured to use standard password authentication or public-private keypairs in lieu of or in addition to a password. In this authentication scenario, the user’s public key must be in a special file on the computer running the server that lists which keypairs are allowed to login as that user (i.e., SSH Authorized Keys).

Detection rules14

Rules on DetectionCode tagged with T1021.004.

Sigma5

RuleLevelLog source
Bitbucket Global SSH Settings Changedmediumbitbucket / NULL
Bitbucket User Login Failure Via SSHmediumbitbucket / NULL
OpenEDR Spawning Command Shellmediumwindows / process_creation
OpenSSH Server Listening On Socketmediumwindows / NULL
Port Forwarding Activity Via SSH.EXEmediumwindows / process_creation

Splunk9

RuleTypeRiskData source
Cisco IOS XE Remote Access Probe BurstAnomalyNULLCisco IOS Logs
Cisco Privileged Account Creation with HTTP Command ExecutionCorrelationNULL
Cisco Privileged Account Creation with Suspicious SSH ActivityCorrelationNULL
Cisco Secure Firewall - SSH Connection to Non-Standard PortAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - SSH Connection to sshd_opernsAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
ESXi SSH EnabledTTPNULLVMWare ESXi Syslog
Linux SSH Remote Services Script ExecuteTTPNULLSysmon for Linux EventID 1
Windows Protocol Tunneling with PlinkTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows PuTTY Suite Utility ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups19

Software5

Campaigns3

Procedure examples27

Groups19

Used byProcedure example
GroupAPT39

APT39 used secure shell (SSH) to move laterally among their targets.

GroupAPT5

APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.

GroupAquatic Panda

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.

GroupBlackTech

BlackTech has used Putty for remote access.

GroupFIN13

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.

GroupFIN7

FIN7 has used SSH to move laterally through victim environments.

GroupFox Kitten

Fox Kitten has used the PuTTY and Plink tools for lateral movement.

GroupGCMAN

GCMAN uses Putty for lateral movement.

View all 19 groups examples

Software5

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can SSH to a remote service.

ToolEmpire

Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection.

MalwareKinsing

Kinsing has used SSH for lateral movement.

MalwareQilin

Qilin can enable SSH access on ESXi hosts.

MalwarereGeorg

reGeorg can communicate using SSH through an HTTP tunnel.

Campaigns3

Used byProcedure example
CampaignC0032

During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution.

CampaignCutting Edge

During Cutting Edge, threat actors used SSH for lateral movement.

CampaignLeviathan Australian Intrusions

Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions.

References3

  1. Sygnia Abyss Locker 2025 Open source
    Abigail See, Zhongyuan (Aaron) Hau, Ren Jie Yow, Yoav Mazor, Omer Kidron, and Oren Biderman. (2025, February 4). The Anatomy of Abyss Locker Ransomware Attack. Retrieved April 4, 2025.
  2. Sygnia ESXi Ransomware 2025 Open source
    Zhongyuan Hau (Aaron), Ren Jie Yow, and Yoav Mazor. (2025, January 21). ESXi Ransomware Attacks: Stealthy Persistence through. Retrieved March 27, 2025.
  3. TrendMicro ESXI Ransomware Open source
    Junestherry Dela Cruz. (2022, January 24). Analysis and Impact of LockBit Ransomware’s First Linux and VMware ESXi Variant. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.