TunnesshClient is a PyInstaller-packaged reverse-SSH backdoor associated with BoryptGrab distribution activity. It establishes a reverse SSH tunnel from compromised Windows systems to attacker-controlled infrastructure, providing persistent remote access. The tunnel can expose SOCKS5 proxy functionality, enabling operators to route traffic through the victim host, and supports remote command execution and file movement. It has been delivered as an additional payload by BoryptGrab-related launchers distributed through SEO-poisoned GitHub repositories, fake software-download pages, and ZIP archives masquerading as legitimate utilities or game cheats. Evidence associated with this distribution ecosystem suggests the operators may be Russian-speaking or Russian-origin, but no definitive attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor nommée dans la liste de logiciels malveillants/outils, sans description de son usage dans cette campagne.
A reverse SSH backdoor reported as a secondary payload in BoryptGrab campaigns, providing persistent remote access.
A malicious PyInstaller reverse-SSH backdoor mentioned as a secondary payload in earlier BoryptGrab-related reporting, not the primary malware in this campaign.
Backdoor enabling reverse SSH tunneling and SOCKS5 proxying for attacker communications and pivoting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.