Threat Advisory

ELF Sshdinjector Malware Targets Remote SSH Daemon Compromise Data and Exfiltration

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components. The malware’s persistence mechanism and data exfiltration capabilities make it particularly dangerous for compromised systems.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ELF Sshdinjector is a malware family targeting SSH daemons, with samples surfacing recently as part of espionage campaigns. The malware is attributed to the DaggerFly group, also known for its involvement in the Lunar Peek campaign. These attacks focus on compromising network appliances by injecting malicious code into critical system components. The malware’s persistence mechanism and data exfiltration capabilities make it particularly dangerous for compromised systems.[emaillocker id="1283"]

The attack begins with a dropper that checks for root privileges and verifies whether the system is already infected by searching for specific files. If no infection is found, the dropper overwrites essential system binaries, such as ls, netstat, and crond, with malicious variants. It also infects the SSH daemon by injecting a malicious library, libsshd.so. This library communicates with a remote command and control (C2) server to exfiltrate system information, including system details, user credentials, and running processes. The malware uses hard-coded IPs and ports to establish communication with the C2 and operates via a custom protocol that ensures stealthy exfiltration. In addition to data theft, malware employs various persistence techniques, including file manipulation and daemon restarts, to maintain control over the compromised system.

It represents a highly targeted and advanced threat leveraging SSH daemon injection for persistent access and data exfiltration. The attack chain involves a series of well-orchestrated steps, from initial infection to remote control by the attacker. While AI-assisted reverse engineering tools significantly aid in understanding the malware, human oversight is crucial to detect potential inaccuracies, hallucinations, and omissions in AI-generated analysis. This highlights the need for a combined approach of automated and manual analysis in defending against such threats.

 

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1190 Exploit Public-Facing Application
Defense Evasion T1222 File and Directory Permissions Modification
Command and Control T1071 Application Layer Protocol
Collection T1005 Data from Local System
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1486 Data Encrypted for Impact

 

REFERENCES:

The following reports contain further technical details:
https://www.fortinet.com/blog/threat-research/analyzing-elf-sshdinjector-with-a-human-and-artificial-analyst

[/emaillocker]
crossmenu