Cyber Security News

Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files

In October 2025, threat researchers at Cyble Research and Intelligence Labs uncovered a sophisticated cyber attack leveraging weaponized military documents to distribute an advanced SSH-Tor backdoor targeting defense sector personnel.

The campaign centers on a deceptively simple delivery mechanism: a ZIP archive disguised as a Belarusian military document titled “ТЛГ на убытие на переподготовку.pdf” (TLG for departure for retraining), specifically designed to lure Special Operations Command personnel specializing in unmanned aerial vehicle operations.

The attack represents a significant evolution in state-sponsored cyber espionage techniques, combining social engineering with sophisticated technical countermeasures to establish persistent backdoor access.

Cyble analysts identified that the malware deploys OpenSSH for Windows alongside a customized Tor hidden service featuring obfs4 traffic obfuscation, granting threat actors anonymous access to SSH, RDP, SFTP, and SMB protocols on compromised systems.

The researchers successfully connected via SSH to confirm the backdoor’s operational functionality, though no secondary payloads or post-exploitation actions were observed at the time of analysis.

Threat attribution analysis suggests moderate confidence alignment with UAC-0125/Sandworm (APT44), a Russian-linked advanced persistent threat group known for targeting Ukrainian military and critical infrastructure since 2013.

Infection chain (Source – Cyble)

The tactical patterns, infrastructure overlaps, and operational methodologies mirror the December 2024 Army+ campaign, demonstrating Sandworm’s continuous refinement of proven attack techniques.

Multi-Stage Infection Mechanism and Evasion Strategy

The attack chain employs nested ZIP archives and LNK file disguises to bypass automated detection systems with remarkable sophistication.

Upon extraction, victims encounter an LNK file appearing as a legitimate PDF alongside a hidden directory named “FOUND.000” containing an additional archive titled “persistentHandlerHashingEncodingScalable.zip.”

SSH connection to the victim host (Source – Cyble)

When the victim attempts opening what appears to be a PDF document, the LNK file executes embedded PowerShell commands, extracting the nested archive to the %appdata%\logicpro directory and retrieving obfuscated PowerShell content for execution.

Cyble analysts identified critical anti-analysis checks embedded within the second-stage PowerShell script. The malware validates that at least 10 recent LNK files exist on the system and confirms the process count exceeds 50—thresholds rarely met in sandbox environments.

This environmental awareness mechanism terminates execution in automated analysis systems while proceeding on genuine user workstations.

Following validation, the script displays a decoy PDF to maintain the illusion of legitimacy while establishing persistence through scheduled tasks configured to execute at logon and daily at 10:21 AM UTC, ensuring continuous access to the compromised infrastructure.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago