Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Attack Activity Analysis Using SSH+TOR Tunnels for Covert Persistence

0b6f7356919b9632c1158681ee0462f3

TLP:CLEAR
Active

md5

Description

APT-C-13 (Sandworm), also known as FROZENBARENTS, is a state-sponsored advanced persistent threat group conducting global cyber espionage targeting government agencies, diplomatic departments, energy enterprises, and research organizations. Recently detected samples reveal the group's use of nested SSH and TOR tunnel architecture to establish covert communication channels. The attack begins with spear-phishing emails delivering malicious LNK files disguised as PDF documents. Upon execution, the payload deploys TOR hidden services mapping internal ports (SMB/445, RDP/3389) to onion domains, while SSH services with public key authentication provide encrypted remote access. The malware employs obfs4 protocol to obfuscate TOR traffic, evading deep packet inspection. Persistence is achieved through scheduled tasks masquerading as legitimate applications like Opera GX and Dropbox, establishing an anonymous shadow management infrastructure for sustained intelligence collection.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Attack Activity Analysis Using SSH+TOR Tunnels for Covert Persistence
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 00:55
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 0b6f7356919b9632c1158681ee0462f3

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.