Kobalos is a sophisticated cross-platform backdoor associated primarily with compromises of Unix-like systems, especially high-performance computing environments and other high-profile organizations. It has been observed targeting SSH infrastructure by embedding itself into the OpenSSH server and, in many cases, pairing that access with a trojanized SSH client used to steal credentials from compromised hosts. Reported victimology includes HPC clusters as well as organizations outside academia and research, indicating broader opportunistic or selective targeting of valuable Linux and Unix environments.
The malware provides covert remote access with capabilities including filesystem access, spawning terminal sessions, and proxying connections through other infected machines. It can chain compromised hosts together as relays, allowing operators to reach downstream targets while obscuring origin and building multi-hop access paths inside victim environments. Kobalos also records host network information such as the target machine’s IP address.
A notable operational characteristic is its frequent implantation into the SSH daemon, where it can be triggered in a stealthy manner by specially crafted connection conditions. Stand-alone variants have also been observed that either listen for inbound connections or communicate with an intermediate command-and-control server. Kobalos contains functionality to run its own command-and-control service, and operators can promote an infected host into a command-and-control node, increasing resilience and flexibility of the intrusion infrastructure.
Kobalos uses encrypted and obfuscated internals to hinder analysis. Its strings are encrypted, authentication and key exchange use RSA-512, and post-authentication traffic is protected with RC4 using a 32-byte password for inbound and outbound communications. It has also been observed modifying timestamps on replaced files to reduce forensic visibility.
Credential theft is an important part of the Kobalos intrusion set. On compromised systems, a trojanized SSH client has been used to capture connection metadata and SSH credentials, supporting lateral movement and expansion to additional servers. The malware’s combination of SSH tampering, credential theft, proxying, and covert remote administration makes it particularly dangerous in clustered and interconnected server environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
“Kobalos’s code is flattened into a single function using a custom packer and its strings are encrypted.”
“No command history related to the attack was found on Kobalos-infected machines.”
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network.
“Kobalos may be triggered by an incoming TCP connection to a legitimate service from a specific source port.”
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/credential-stealing malware that modifies timestamps of replaced files such as trojanized ssh/sshd binaries.
Records the IP address of target machines.
Enterprise New Software: ... Kobalos
Backdoor whose post-authentication channel uses RC4 with a 32-byte password for bidirectional traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.