EXECUTIVE SUMMARY:
ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components. The malware’s persistence mechanism and data exfiltration capabilities make it particularly dangerous for compromised systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components. The malware’s persistence mechanism and data exfiltration capabilities make it particularly dangerous for compromised systems.[emaillocker id="1283"]
The attack begins with a dropper that checks for root privileges and verifies whether the system is already infected by searching for specific files. If no infection is found, the dropper overwrites essential system binaries, such as ls, netstat, and crond, with malicious variants. It also infects the SSH daemon by injecting a malicious library, libsshd.so. This library communicates with a remote command and control (C2) server to exfiltrate system information, including system details, user credentials, and running processes. The malware uses hard-coded IPs and ports to establish communication with the C2 and operates via a custom protocol that ensures stealthy exfiltration. In addition to data theft, malware employs various persistence techniques, including file manipulation and daemon restarts, to maintain control over the compromised system.
It represents a highly targeted and advanced threat leveraging SSH daemon injection for persistent access and data exfiltration. The attack chain involves a series of well-orchestrated steps, from initial infection to remote control by the attacker. While AI-assisted reverse engineering tools significantly aid in understanding the malware, human oversight is crucial to detect potential inaccuracies, hallucinations, and omissions in AI-generated analysis. This highlights the need for a combined approach of automated and manual analysis in defending against such threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Defense Evasion | T1222 | File and Directory Permissions Modification |
| Command and Control | T1071 | Application Layer Protocol |
| Collection | T1005 | Data from Local System |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
https://www.fortinet.com/blog/threat-research/analyzing-elf-sshdinjector-with-a-human-and-artificial-analyst