Abuse of Windows SSH ProxyCommand and LocalCommand for Code Execution
Attackers are abusing Windows SSH configuration features 'ProxyCommand' and 'LocalCommand' to execute arbitrary scripts and establish command-and-control channels via living-off-the-land binaries.
Adversaries are increasingly leveraging built-in Windows SSH client functionality as a mechanism for executing arbitrary commands, bypassing traditional security controls. By manipulating the 'ProxyCommand' or 'LocalCommand' arguments within an SSH connection string, attackers can trigger the automatic execution of child processes when an SSH session is initiated or a proxy connection is established. This technique is particularly effective for 'Living off the Land' (LotL) operations, as it abuses legitimate, trusted binaries to execute malicious payloads or scripting engines like PowerShell, mshta, or wscript.
This activity has been observed in various contexts, including command-and-control (C2) operations and the delivery of secondary payloads. By embedding commands within the SSH configuration, attackers effectively mask their activity under the guise of legitimate SSH traffic and process execution, making it difficult for defenders to distinguish malicious intent without deep visibility into parent-child process relationships and process command-line arguments.
Attack Chain
- Attacker gains access to a Windows host where the SSH client (ssh.exe) is installed and available.
- Attacker prepares a malicious SSH configuration or command string containing 'ProxyCommand' or 'PermitLocalCommand=yes' combined with a 'LocalCommand' payload.
- Attacker executes 'ssh.exe' using the malicious configuration string via command line, script, or a scheduled task.
- The 'ssh.exe' process initializes and evaluates the provided command-line arguments.
- 'ssh.exe' spawns a child process corresponding to the specified 'ProxyCommand' or 'LocalCommand' (e.g., powershell.exe, mshta.exe, or cscript.exe).
- The child process executes the embedded malicious payload, such as a web request to retrieve a secondary stage or a local script execution.
- Final objective is achieved, such as C2 beaconing, persistence, or data exfiltration.
Impact
Successful exploitation allows for unauthorized code execution with the privileges of the user running the SSH client. This technique facilitates command-and-control communication, the execution of memory-resident malware, and the obfuscation of post-exploitation activities. It has been associated with ransomware campaigns and other malicious operations that rely on native binaries to evade detection.
Recommendation
Prioritize the monitoring of SSH process spawning behavior to identify suspicious child processes.
- Deploy the provided Sigma rule to your SIEM/EDR to detect suspicious child processes spawned by ssh.exe.
- Enable EDR process-creation logging (e.g., Sysmon Event ID 1) across all workstations and servers.
- Audit SSH configuration files and command-line usage patterns to identify unauthorized use of 'ProxyCommand' or 'LocalCommand' features.
- Use the Splunk Common Information Model (CIM) to ensure process telemetry is correctly normalized for efficient detection.
Immediate actions
Deploy the Sigma rule to monitor for suspicious SSH child processes
Threat Hunt
Search for instances of ssh.exe spawning powershell, mshta, or wscript
Data: Process creation logs (Event ID 1)
Detection coverage 1
Detect Suspicious SSH ProxyCommand or LocalCommand Child Processes
mediumDetects instances where ssh.exe spawns suspicious child processes like PowerShell, mshta, or wscript via ProxyCommand or LocalCommand arguments.
Detection queries are available on the platform. Get full rules →