Researchers documented Linux/SSHDoor.A, a trojanized OpenSSH daemon that steals usernames and passwords from compromised Linux servers while giving attackers covert persistent access. The malware exfiltrates server and credential data over HTTP after encrypting it with an embedded 1024-bit RSA key and Base64-encoding the result, and it can preserve access through a hardcoded password or bundled SSH key, with override options read from /var/run/.options. ESET linked the activity to infrastructure including openssh.info and linuxrepository.org, which at the time resolved to 82.221.99.69, and a later sample shared publicly was detected by multiple antivirus engines as an SSH backdoor.
The SSH backdoor was also observed alongside Linux/Chapro.A, a malicious Apache module used to inject iframes into web traffic, delivering a Java exploit for CVE-2012-1723 and ultimately a Zeus/Zbot payload to Windows victims. In later research, ESET expanded the picture beyond SSHDoor, identifying 21 undocumented or underdocumented Linux malware families built from trojanized OpenSSH binaries; 18 stole credentials and 17 provided stealth backdoor access. The findings showed that OpenSSH backdoors remained an active and diverse threat on Linux servers, ranging from simple credential theft to more advanced families using encrypted HTTP, raw TCP, or DNS for command and control.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
ESET released "The Dark Side of the ForSSHe," a white paper covering 21 previously undocumented or underdocumented Linux malware families built from trojanized OpenSSH binaries. The research drew on more than three years of sample hunting and honeypot collection and found that most families stole credentials and many also provided stealthy persistent access.
ESET reported that the command-and-control domain for the Kessel OpenSSH backdoor family was registered in August 2018. The registration suggested Kessel was a relatively new family at the time of ESET's publication.
ESET published technical analysis of Linux/SSHDoor.A, describing it as a trojanized SSH daemon that steals usernames and passwords and provides covert remote access. The report also linked it with Linux/Chapro.A and identified exfiltration hostnames openssh.info and linuxrepository.org.
ESET stated that the Kamino OpenSSH backdoor was first used in a crimeware campaign involving DarkLeech traffic redirection. This established an early known use of Kamino before later reporting tied it to other operations.
The Windows Zeus/Zbot payload delivered through the Linux/Chapro.A infection chain was listed on VirusTotal with a detection ratio of 32/44. This reflected the final stage of the cross-platform campaign from compromised Linux servers to Windows victims.
A malicious Apache module identified as Linux/Chapro.A was listed on VirusTotal with a detection ratio of 19/46. The malware was used to inject malicious iframe content into Apache-served web traffic.
A ZIP archive used in the Linux/Chapro.A delivery chain, exploiting CVE-2012-1723 in Java, was listed on VirusTotal with a detection ratio of 2/43. The sample was identified as part of a multi-stage campaign that ultimately delivered Zeus/Zbot malware.
A Linux SSHDoor ELF sample with MD5 90dc9de5f93b8cc2d70a1be37acea23a was scanned on VirusTotal, where 22 of 46 engines detected it as SSHDoor or a Linux SSH backdoor. The sample matched the malware family previously described by ESET as Linux/SSHDoor.A.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcecontagiodump.blogspot.com
Open sourcewelivesecurity.com
Open sourcecontagiodump.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.