reverse_ssh is an open-source SSH-based reverse shell tool written in Go that is used to establish persistent remote access from compromised systems to attacker-controlled infrastructure. It functions by initiating outbound SSH connections from the victim, which can help bypass perimeter controls that more readily block inbound management access. The tool supports reverse shell access as well as local and remote dynamic port forwarding, enabling operators to pivot within victim environments and facilitate lateral movement. It also includes SCP and SFTP functionality that can be used to stage tools and exfiltrate data.
The tool has been observed deployed after exploitation of internet-exposed VMware vCenter systems, where it was used to maintain persistence following remote code execution through the vCenter Syslog service vulnerability CVE-2026-59310. It has also appeared as a component or code dependency in other malware, including Go-based backdoors such as GoReShell, which reuse reverse_ssh functionality to create reverse SSH channels. In supply-chain compromise activity targeting developers, Linux payloads linked to a malicious npm package were identified as clients of the reverse_ssh project.
reverse_ssh is not inherently malicious as an open-source administrative utility, but in intrusion operations it is used as a post-exploitation access mechanism. Observed abuse spans persistence, remote command execution, tunneling, file transfer, and support for follow-on movement inside victim networks. Reported victimology associated with its malicious deployment includes enterprise virtualization infrastructure and broader espionage or opportunistic exploitation campaigns affecting organizations across multiple countries and sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-59310 — Directory Traversal. VMware vCenter contiene una vulnerabilidad de directory traversal (recorrido de directorios) en el servidor Syslog. Un atacante con acceso de red a vCenter puede explotar esta vulnerabilidad para ejecutar código arbitrario.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
...seguidos del despliegue de un cron job malicioso para establecer persistencia mediante reverse_ssh, una herramienta de código abierto utilizada para establecer conexiones SSH hacia infraestructura controlada por los atacantes.
CVE-2026-59310 está siendo explotada activamente... La actividad observada incluye intentos de path traversal compatibles con la vulnerabilidad... Adicionalmente, Defused Cyber ha observado un aumento del escaneo contra VMware vCenter, indicativo de posibles esfuerzos de explotación dirigidos contra CVE-2026-59309.
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections
Unspecified attackers are actively exploiting a critical 9.8 directory traversal flaw in VMware vCenter systems across 361 unique victim IP addresses in 47 countries... A directory traversal vulnerability lets an attacker manipulate file paths to reach directories and files they should never touch, then execute code across an enterprise’s virtual environment.
Quirso, said a threat actor has been exploiting CVE-2026-59310 and using reverse secure shell (SSH) to maintain access to compromised systems... Quirso’s reported attack chain used a cron job (time-based task scheduler) and reverse_ssh to create an outbound connection to attacker infrastructure.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An SSH-based reverse-shell tool used post-exploitation to establish persistent backdoor access, maintain outbound connect-backs, enable port forwarding for lateral movement, and support SCP/SFTP file transfer and exfiltration.
Open-source Golang reverse shell client deployed on Linux as part of the ambar-src infection chain, enabling remote interactive access/pivoting from compromised developer hosts.
Open-source tool providing reverse SSH capability; its functionality is leveraged by GoReShell to create attacker-controlled reverse SSH access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.