Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

chinesemalwarslinuxsshbackdoor-mandvi2025

2025-11-02

Chinese Hackers Target Linux Devices with New SSH Backdoor

February 5, 2025

https://cyberpress.org/chinese-hackers-target-linux-devices/

Notes
Linux malware
SSH malware
Daggerfly Evasive Panda
cyberespionage
sshdinjector
persistence
IoT
network appliances
supply chain attack
targets Asia and United States
dropper
root user
libsshd.so
backdoor
command and control
overwrites netstat, ls, and crond
exfiltrates MAC address, credentials, and system logs
RCE
c2 uses custom protocol
Chinese phrases for laughter found in samples: heihei xixi
ELF

Links to this note

  • Notes

Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.