Cyber Security News

New SSH-Snake Malware Abuses SSH Credentials To Spread Itself In The Network

Threat actors abuse SSH credentials to gain unauthorized access to systems and networks. By exploiting weak or compromised credentials, they can execute malicious activities.

SSH credential abuse provides a stealthy entry point for threat actors to compromise and control the targeted systems.

On January 4th, 2024, the Sysdig Threat Research Team (TRT) discovered a network mapping tool dubbed SSH-Snake that was being used as a self-propagating worm.

The tool was found to be exploiting SSH credentials in its attempt to spread and infect other systems. As a result, it poses a significant threat to network security and should be handled with caution.

It hunts for credentials and shell history for its next targets, and currently, threat actors are actively using SSH-Snake malware.

SSH-Snake Malware Abuses SSH Credentials

After gaining system access, attackers often use lateral movement to find and reach other targets. Previous research uncovered a worm seeking SSH credentials to connect and repeat the process.

Document
Analyse Shopisticated Malware with ANY.RUN

Try ANY.RUN Yourself with a 14-day Free Trial

More than 300,000 analysts use ANY.RUN is a malware analysis sandbox worldwide. Join the community to conduct in-depth investigations into the top threats and collect detailed reports on their behavior..

The lateral movement of SSH-Snake is great in private key finding. It can evade scripted attack patterns to provide stealthiness, flexibility, configurability, and better credentials discovery. It is more efficient and successful than normal SSH worms.

SSH-Snake malware automates network traversal with discovered SSH private keys, mapping a network and dependencies. 

A bash script that autonomously seeks SSH credentials on the system by logging into targets and replicating to repeat the process. However, the results aid the threat actors in ongoing operations. 

Output of SSH-Snake in a very small network (Source – Sysdig)

SSH-Snake self-modifies to shrink its size by removing comments, whitespace, and unnecessary functions for fileless operation. 

Its initial form is larger for enhanced functionality, and it works on any device by self-replicating and is fileless.

SSH-Snake automates the laborious task of discovering SSH-connected systems, which allows saving time and effort.

Here below, we have mentioned all the automated tasks that the SSH-Snake performs:-

  • On the current system, find any SSH private keys,
  • On the current system, find any hosts or destinations (user@host) that the private keys may be accepted,
  • Attempt to SSH into all of the destinations using all of the private keys discovered,
  • If a destination is successfully connected to, repeat steps #1 – #4 on the connected-to system.

This malware hunts various private key types on the target system using diverse methods. It scans bash history for SSH-related commands by revealing the key locations and credentials. 

Sysdig TRT found the C2 server of SSH-Snake deployers. The server houses SSH-Snake’s output for each target that helps in revealing victim IPs.

Exposed assets (Source – Sysdig)

CNCF incubates Falco and offers real-time alerts for cloud-native rarities. Users can deploy default or custom rules easily. Detect SSH-Snake with default rules or craft new ones for better detection. 

SSH-Snake enhances threat actor capabilities, enabling the exploitation of SSH keys that help evade static detection.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago