Win32/SSHBearDoor.A is a trojanized Dropbear SSH server used as a backdoor to maintain persistent access on compromised Windows systems. In the referenced investigations, the binary appeared to be a legitimate Dropbear SSH server but contained a hidden backdoor. ESET reports that it authenticates users using a hardcoded password and a specific private key. The malware was observed in 2015 in operations attributed in the content to the BlackEnergy group, alongside BlackEnergy and the destructive KillDisk component. Those campaigns targeted Ukrainian news media and the electric power industry, including incidents around the 2015 Ukrainian local elections. The broader intrusion set also involved malicious XLS documents with macros as part of the infection chain, although the provided content specifically describes SSHBearDoor.A as a persistence mechanism rather than the initial infection vector. The content does not provide standalone hashes or network indicators specifically for SSHBearDoor.A, but explicitly identifies it as ESET detection name Win32/SSHBearDoor.A.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Win32/SSHBearDoor.A is a backdoored version of the Dropbear SSH server, allowing attackers persistent access via hardcoded credentials or a specific key pair. It was used by the BlackEnergy group as an additional access channel to compromised systems.
Win32/SSHBearDoor.A is a backdoored version of the Dropbear SSH server, allowing attackers persistent access via hardcoded credentials or a specific key pair. It was used by the BlackEnergy group as an additional access channel to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.