reverse_ssh is an open-source, Go-based reverse-shell utility that uses outbound SSH connections to provide remote access to compromised systems. It is dual-use tooling employed by attackers during post-exploitation, rather than an exclusively malicious software family. Its capabilities include local and remote dynamic port forwarding and SCP/SFTP file transfers, supporting lateral movement, payload staging, and file exfiltration. Repeated outbound connection attempts help maintain access, while outbound control connections on standard ports can bypass perimeter restrictions.
Attackers have deployed reverse_ssh on VMware vCenter appliances following exploitation of CVE-2026-59310 in the Syslog server component, using malicious cron jobs to maintain persistence. A Linux reverse_ssh client has also been distributed through a malicious npm package that executes download-and-run commands during installation, exposing developer systems to compromise. Separately, the Windows backdoor GoReShell incorporates reverse_ssh functionality to establish reverse SSH connections. GoReShell has been associated with PurpleHaze, a China-nexus intrusion cluster; that association does not establish exclusive attribution for the underlying open-source utility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-59310 (CVSS score: 9.8) - A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code. The vulnerability affecting VMware vCenter is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor to deploy a backdoor along with reverse_ssh binaries for persistent access to compromised instances. In at least one case, the campaign has led to the deployment of a Babuk-derived ransomware.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
After code execution, the attacker deployed a malicious cron job running reverse_ssh ... for persistent outbound access.
TTP # T1059 — Command and Scripting Interpreter (Execution)
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
After code execution, the attacker deployed a malicious cron job running reverse_ssh ... for persistent outbound access.
Quirso, said a threat actor has been exploiting CVE-2026-59310 and using reverse secure shell (SSH) to maintain access to compromised systems... Quirso’s reported attack chain used a cron job (time-based task scheduler) and reverse_ssh to create an outbound connection to attacker infrastructure.
The linuxFile implant is designed to provide remote command execution capabilities to the attacker. It establishes a connection to its controller over a WebSocket channel to receive instructions
TTP # T1071.002 — Application Layer Protocol: File Transfer Protocols (Command and Control)
The reverse SSH connection provides an outbound command-and-control (C2) channel and can also help bypass firewalls or other network security measures.
In the next step, a curl command (or alternatively a wget command) is executed to retrieve a backdoor from "5.34.177[.]38:9861" and execute it, and then remove the log file.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used via a malicious cron job to provide persistent reverse SSH access on compromised VMware vCenter systems after exploitation of CVE-2026-59310.
An SSH-based reverse-shell tool used post-exploitation to establish persistent backdoor access, maintain outbound connect-backs, enable port forwarding for lateral movement, and support SCP/SFTP file transfer and exfiltration.
Open-source Golang reverse shell client deployed on Linux as part of the ambar-src infection chain, enabling remote interactive access/pivoting from compromised developer hosts.
Open-source tool providing reverse SSH capability; its functionality is leveraged by GoReShell to create attacker-controlled reverse SSH access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.