Detection of OpenSSH Backdoor Activity on Linux
This detection logic identifies adversaries attempting to maintain persistence or harvest credentials by modifying OpenSSH binaries or configuration files, resulting in suspicious file creation events.
What's new
- 1. new product Oct 8, 19:05 via elastic
Adversaries frequently target OpenSSH to facilitate persistence or credential theft by patching sensitive functions within ssh or sshd binaries. This activity often involves modifying binary integrity or injecting malicious code that logs authentication credentials to localized files. The behavior manifests through the creation of files with unusual extensions, hidden naming conventions (e.g., dot-files), or staging activity within sensitive directories like /tmp, /var/tmp, or system library paths. Defenders should monitor for suspicious file creation events originating from ssh-related processes, as these often indicate the presence of a backdoor or an attempt to exfiltrate cached session data.
Attack Chain
- Attacker gains initial access to the Linux host via an unrelated vulnerability.
- Attacker escalates privileges to root to gain write access to system binaries.
- Attacker modifies the OpenSSH binary (sshd) or injects a shared object library to hook authentication functions.
- Attacker creates hidden or masqueraded log files (e.g., .sshd_auth) to stage captured credentials.
- Attacker stores temporary session data or malicious configuration files in world-writable directories such as /tmp or /var/tmp.
- Attacker leverages the modified OpenSSH binary to persist in the environment and capture incoming user credentials.
Impact
Successful exploitation allows for long-term persistence within the targeted Linux environment, unauthorized remote access, and the potential harvesting of user credentials as they authenticate via the SSH protocol. This creates a significant risk of lateral movement and full system compromise if credentials for administrative accounts are intercepted.
Recommendation
Deploy the provided Sigma rule to monitor for suspicious file creation events associated with OpenSSH processes. Perform baseline integrity checks on ssh and sshd binaries using file hash comparisons. Investigate any alerts by verifying the associated user context and inspecting the contents of files created in sensitive directories like /tmp or /dev/shm. Ensure that automated configuration management tools like Ansible are excluded from these detection rules to minimize false positive noise.
Immediate actions
Deploy the Sigma rule to monitor for file creation by ssh/sshd.
Mitigations
Review SSH binary integrity via cryptographic checksums.
T1554
Detection coverage 1
Potential OpenSSH Backdoor Logging Activity
lowIdentifies suspicious file creation by ssh or sshd processes, which may indicate backdoor persistence or credential staging.
Detection queries are available on the platform. Get full rules →