SSHdInjector is a Linux SSH backdoor that injects malicious code into the SSH daemon (sshd) at runtime. The injected code provides persistent access for the operator and supports credential theft, remote command execution, malware ingress, file and directory access, opening a remote shell, and data exfiltration. Reporting cited in the content links SSHdInjector to China-nexus threat actors, including Digging Taurus (also known as Daggerfly/Evasive Panda), and states that it has targeted government and telecommunications organizations. Unit 42 included SSHdInjector among actively updated ELF malware families used against cloud infrastructure, noting Linux prevalence in cloud environments and describing SSH daemon injection as one of the key techniques used by these threats. Additional content notes that YARA detection rules were added for the Sshdinjector backdoor based on specific string patterns related to its operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SSHdInjector is a Linux SSH backdoor that injects code into the SSH daemon at runtime, enabling persistent access, credential theft, remote command execution, and data exfiltration. It is used by China-nexus threat actors for cyberespionage.
Linux backdoor detected via YARA using string patterns indicative of its operational behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.