Talk With an Expert

Analysis of a Multi-Architecture SSH Linux Backdoor

Analysis of a Multi-Architecture SSH Linux Backdoor (PDF, 5.83MB)Published: 17 Jun, 2019
Created by
Angel Alonso-Parrizas

A key aspect in any intrusion is to attempt to gain persistence on the compromised system. Threat actors and criminals assure persistence through different mechanisms including backdoors. The existence of backdoors is nothing new and over the years very popular backdoors targeting most Operating Systems and many application have been developed. This paper focuses on the code analysis of an SSH Linux backdoor used in the wild by a criminal group from 2016 to at least October 2018. The backdoor runs in multiple architectures; however, the research focuses on the ARM version of the backdoor using the recently released reversing tool Ghidra, which has been developed by the NSA.