SSH-Tor Backdoor Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 9, 2025
Last Seen
November 9, 2025

SSH-Tor Backdoor is a malware family tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 9, 2025; most recent activity November 9, 2025.

Overview

The SSH-Tor Backdoor is a malware family that creates covert remote access by combining SSH-based channels with Tor-anonymized C2 traffic. It leverages SSH for persistence and uses Tor to route communications, enabling attackers to operate with strong anonymity and evade network monitoring. This dual-use approach makes it significant for defenders because it complicates attribution and detection on compromised systems.

Related Threat Clusters

  • Emerging Malware Threats Targeting Defense and Software Systems

    Recent malware developments include the SesameOp backdoor utilizing OpenAI Assistants API for command and control, and advanced SSH-Tor backdoors targeting the defense sector. Additionally, Gootloader has resurfaced…

    2 articles · Updated November 9, 2025
  • Emerging Malware Threats Exploiting New Delivery Methods

    Recent malware campaigns have been identified utilizing innovative techniques for delivery and execution. Notable threats include the use of JSON storage services for malware delivery and the resurgence of Gootloader,…

    5 articles · Updated November 23, 2025

Recent Intelligence Reports

  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 70 — Securityaffairs.Co · November 9, 2025

CVSS v3.1 Breakdown