SSH-Tor Backdoor is a malware family tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 9, 2025; most recent activity November 9, 2025.
The SSH-Tor Backdoor is a malware family that creates covert remote access by combining SSH-based channels with Tor-anonymized C2 traffic. It leverages SSH for persistence and uses Tor to route communications, enabling attackers to operate with strong anonymity and evade network monitoring. This dual-use approach makes it significant for defenders because it complicates attribution and detection on compromised systems.
Recent malware developments include the SesameOp backdoor utilizing OpenAI Assistants API for command and control, and advanced SSH-Tor backdoors targeting the defense sector. Additionally, Gootloader has resurfaced…
Recent malware campaigns have been identified utilizing innovative techniques for delivery and execution. Notable threats include the use of JSON storage services for malware delivery and the resurgence of Gootloader,…