The 'sshd_trojan_(elf_binary)' is a malicious ELF binary designed to masquerade as the legitimate OpenSSH daemon, enabling persistence and evasion on compromised Linux systems. Captured on November 10, 2025, during a honeypot operation, the trojan was deployed following a successful SSH brute force attack using default root credentials. The attacker maintained a brief session, uploaded only the trojan, and executed no further commands, minimizing detection risk. Analysis mapped the malware's capabilities to several MITRE ATT&CK techniques, including credential dumping (T1003.008), masquerading (T1036.005), sandbox evasion (T1497), and privilege escalation (T1548.001). The binary was confirmed malicious by VirusTotal and Hybrid-Analysis. The attack demonstrates advanced persistence and evasion tactics, leveraging legitimate-looking binaries and minimal activity. The use of a government IP address as the attack source was assessed as likely due to prior compromise, not direct nation-state involvement. The incident highlights the sophistication of current threat actors targeting Linux systems via SSH brute force and the importance of robust authentication and detection controls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.