Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Bonadan

Bonadan

TLP:CLEAR
Family

AI Analysis

· 3 hours ago

Executive Summary

Bonadan is an SSH impersonation backdoor targeting Linux servers that covertly mines cryptocurrency and steals credentials by exploiting legitimate OpenSSH flows. Its dual functionality enables attackers to profit from mining while compromising authentication data for lateral movement or phishing. Detection and mitigation require scrutinizing unusual OpenSSH processes, monitoring excessive CPU usage, and blocking unauthorized credential exfiltration.

Enhanced Description

Bonadan is a Linux‑based backdoor that masquerades as a legitimate OpenSSH server to evade detection by appearing as trusted infrastructure. First observed in 2018, the malware replaces or injects itself into the OpenSSH service, maintaining low visibility while listening for remote commands over standard SSH ports. Once connected, it can execute arbitrary shell commands, exfiltrate data, and persist through system reboots. In addition to acting as a stealthy command‑and‑control agent, Bonadan includes two key malicious modules. The first is a cryptocurrency–mining component that exploits CPU resources to mine coins such as Monero; this module drains system performance and can elevate the attacker’s revenue. The second module is a credential‑stealing payload closely related to those found in the Onderon family of backdoors, harvesting user credentials from SSH login attempts or local authentication files before forwarding them to remote egress points. Together, these capabilities allow attackers to conduct illicit background operations while quietly siphoning system resources and compromising identities. The combination of legitimate service impersonation, stealthy persistence, ransomware‑like exfiltration of credential data, and covert cryptocurrency mining makes Bonadan a multi‑faceted threat that can be leveraged for espionage, financial gain, or as part of a larger botnet. The use of OpenSSH as a delivery vector also enhances the attack’s stealth by utilizing encrypted traffic over expected ports, complicating detection efforts.

Key Capabilities

  • Impersonates OpenSSH over standard SSH ports
  • Persistent backdoor with root access on compromised systems
  • Remote command execution via shell
  • Cryptocurrency mining module consuming CPU resources
  • Credential‑stealing payload derived from Onderon family
  • Exfiltrates stolen credentials to command & control servers

ATT&CK Techniques

T1059.001
T1110.001
T1078
T1003
T1049
T1497

Recommended Actions

  • Verify integrity of /usr/sbin/sshd and related binaries; replace or quarantine tampered files
  • Audit scheduled jobs for unfamiliar cron entries that spawn mining processes
  • Deploy host‑based intrusion detection to flag unusual SSH connection patterns and high CPU usage
  • Implement strict firewall rules limiting inbound SSH from known IPs using public key authentication only
  • Enforce least privilege by disabling root login over SSH when possible
  • Use application whitelisting to block execution of unauthorized binaries
  • Apply patching for OpenSSH vulnerabilities and keep the software updated

Suggested Tags

linux
openssh backdoor
cryptocurrency miner
credential theft
Onderon family
remote service abuse

Confidence Assessment

The data originates from a single vendor report with limited sample detail, providing basic functional description but lacking in‑depth technical analysis or evidence of widespread deployment. Confidence is moderate regarding core behaviors (OpenSSH masquerading, mining, credential theft) but uncertain about persistence mechanisms, scope, and full threat impact.

Description

Bonadan is a malicious version of OpenSSH which acts as a custom backdoor. Bonadan has been active since at least 2018 and combines a new cryptocurrency-mining module with the same credential-stealing module used by the Onderon family of backdoors.(Citation: ESET ForSSHe December 2018)

Details

Type
Malware
Platforms
Linux
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.