Attack Activity Analysis Using SSH+TOR Tunnels for Covert Persistence
April 29, 2026, 7:44 a.m.
Description
APT-C-13 (Sandworm), also known as FROZENBARENTS, is a state-sponsored advanced persistent threat group conducting global cyber espionage targeting government agencies, diplomatic departments, energy enterprises, and research organizations. Recently detected samples reveal the group's use of nested SSH and TOR tunnel architecture to establish covert communication channels. The attack begins with spear-phishing emails delivering malicious LNK files disguised as PDF documents. Upon execution, the payload deploys TOR hidden services mapping internal ports (SMB/445, RDP/3389) to onion domains, while SSH services with public key authentication provide encrypted remote access. The malware employs obfs4 protocol to obfuscate TOR traffic, evading deep packet inspection. Persistence is achieved through scheduled tasks masquerading as legitimate applications like Opera GX and Dropbox, establishing an anonymous shadow management infrastructure for sustained intelligence collection.
Tags
Date
- Created: April 28, 2026, 8:09 a.m.
- Published: April 28, 2026, 8:09 a.m.
- Modified: April 29, 2026, 7:44 a.m.
Indicators
- 42910bf2aa4ac9d62e2b32e6fadc42f11bd7215fee492ecf72cfd6238965d066
- 1fbdb99357ace6d6db830c63850a6e8a4ea3607776c4668feb135f3ff0d95151
- 6df9cb909b321c24656b218a06dad56bb7916d8ce7de2342321f648af0124e56
- bbcdb82918f0decb1d6e20c90e872175cf278006948c5995ffd88033f56a1b71
- 54148383c8a8a5e51cf4892702f14176110beccd377af75cb184805b6a20986b
- 111e42c31f8e4ae3764f339d7ad04b20bb21be5d97ede13aaa7c73e72cb7549d
- 2a9b971c835e2ee5f190d068c602601fdaf718d8bfe085c2032d59a6f25ed082
- 0a78005858bef767b39cfbbeb543a80dfde46807ee75594de77d3ddfe119e8b5
- 63297928883b0dc4e0735963dbcb2b2fa0c1e131af6d486f882070a6eb7e339a
- a79b5162f9a49df3db4f001325938b9dc7bdc471b71108ed178350c89252e3a5
Additional Informations
- Energy
- Defense
- Government
- e3mnde5uyuxjoztup6t3m7nykbicexbzra76ucligwgsaez65w63y2ad.onion
- imnlyhj4mtmtesqrvf7c4ma6dkxeyxw3ae53w6fuz42spndg7zpat6qd.onion
- 3xl6xhboulyuez6fuydyhj7pdvkshzn4ogsmgwbb3ukrkvgi6bcwvfyd.onion
- nytiplwknkinobjaeb5tajjiglip3vtaccju6ta7d47u5u64ktrwhrqd.onion
- kvk46su7d2qi6g4n43syp4zbsf2rihnc6ztj77qtc2ojvewjqvqilnqd.onion
- 2zrek3mkl72d5b6evpkx2rz2glzrltiorgblpfb2ttg6lacwlsdk4iqd.onion