Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks
Logo

Home

News

Travel Insurance

Chinese Cyberspies Deploy New Ssh Backdoor In Network Device Attacks

Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks

Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks

Evasive Panda, also known as DaggerFly, has been actively targeting network appliances since mid-November 2024 by injecting a novel malware into the SSH daemon (SSHD). This malware, designated “ELF/Sshdinjector.A!tr” by Fortinet’s FortiGuard Labs, allows attackers to hijack SSHD processes, facilitating persistent access and clandestine operations on compromised devices. Upon breaching a system, the attackers deploy a dropper component that verifies if the device is already infected and confirms it operates under root privileges. If these conditions are met, multiple binaries, including a malicious SSH library named “libssdh.so,” are installed. This library serves as the primary backdoor, enabling the attackers to execute a wide range of malicious activities. Evasive Panda has a history of sophisticated cyber-espionage campaigns, including recent supply chain attacks via ISPs in Asia and intelligence gathering from U.S. organizations. This latest development underscores the group’s evolving tactics and the ongoing threat posed by state-sponsored cyber actors.

Was this article helpful?

Secure Your Future Today!

Share your details to explore
the best insurance options for you.

Secure Your Future Today!Secure Your Future Today!

Popular News

Popular News

Latest News

Latest News
Easiest way to manage your HDFC ERGO policies is Here

Download our new mobile app Here to manage your insurance policies

Here QR

Scan To Download