Kessel

MITRE ATT&CK: S0487 View on attack.mitre.org

Aliases: Kessel

First seen
2018-08-01 00:00:00
Malware type
backdoor, botnet, credential-stealer
Family
Malware family
Operating systems
linux
Profile updated
2026-07-07 14:24:26

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot. Kessel has been active since its C2 domain began resolving in August 2018.

Detection coverage

  • 254 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Proxy (attack-pattern)
  • Modify Authentication Process (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)

Reports & references

  • ESET — Eset The Dark Side Of The Forsshe (report)
  • MITRE ATT&CK — S0487 (report)

External references