Skip to content
Threat Feed
low advisory updated

Detection of Unauthorized SSH Binary and Library Modification

Adversaries modify critical SSH binaries and libraries on Linux systems to establish persistence, gain unauthorized access, or harvest credentials through patched sensitive functions.

What's new

  • 1. new product Oct 8, 19:07 via elastic

Adversaries targeting Linux environments may attempt to compromise the integrity of the OpenSSH suite to maintain long-term access or facilitate credential theft. By modifying binaries such as /usr/bin/ssh, /usr/bin/scp, /usr/bin/sftp, /usr/sbin/sshd, or linked libraries like libkeyutils.so, attackers can patch internal functions. These modifications enable malicious actors to capture cleartext credentials during authentication or create backdoors that bypass standard access controls. This activity typically occurs post-exploitation when an attacker has achieved sufficient privileges to modify system-level files. Monitoring for unauthorized changes to these specific sensitive paths is critical for identifying potential subversion of the operating system's primary secure communication mechanism. Defenders must distinguish these malicious modifications from legitimate software updates and administrative maintenance activities.

Impact

Successful modification of SSH binaries results in a complete compromise of the affected host's secure remote access. Attackers gain the ability to exfiltrate valid user credentials as they are entered, effectively turning the SSH server into a credential harvesting tool. This often leads to lateral movement within the network as compromised accounts are reused across other systems. If not detected, such persistence mechanisms can remain active indefinitely, allowing attackers to maintain access even if primary entry points are remediated.

Recommendation

  • Implement File Integrity Monitoring (FIM) or use EDR solutions to monitor modification events on critical binaries: /usr/bin/scp, /usr/bin/sftp, /usr/bin/ssh, /usr/sbin/sshd, and libkeyutils.so.
  • Deploy the Sigma rules below to your SIEM to alert on unauthorized file changes.
  • Establish an allowlist for known-good update processes (e.g., dnf, apt, yum, packagekitd) to minimize false positives during system maintenance.
  • Investigate any process modifying these binaries that does not originate from a recognized package manager or administrative update task.
  • Regularly audit system binaries for signature mismatches or unexpected file size variations.

Immediate actions

Deploy the Sigma detection rule to monitor critical SSH file integrity

Detection Engineering 72h

Mitigations

Enable integrity monitoring and restrict write access to /usr/bin and /usr/sbin directories to root-only and service-account-restricted processes

medium_term IT Operations

T1554

Detection coverage 1

Detect Unauthorized Modification of OpenSSH Binaries

low

Detects unauthorized modifications to OpenSSH binaries and critical libraries that may indicate persistence or credential theft attempts.

sigma tactics: persistence techniques: T1554 sources: file_event, linux

Detection queries are available on the platform. Get full rules →