Dropbear SSH is a lightweight Secure Shell implementation that has been repurposed by threat actors as a remote-access backdoor and persistence mechanism, particularly on embedded and resource-constrained systems. In intrusion activity affecting operational technology environments, attackers deployed Dropbear SSH on victim endpoints and cellular modems to maintain remote access over SSH. Its use has been documented in attacks against internet-exposed industrial control and operational technology assets, including programmable logic controller environments in U.S. critical infrastructure sectors such as government services and facilities, water and wastewater, and energy. A modified Dropbear SSH client was also used by Sandworm during the 2015 Ukraine electric power attack as a backdoor on target systems, including use with a hardcoded backdoor password for persistent access. In these contexts, Dropbear SSH functioned as a legitimate remote administration utility turned into an adversary-controlled access channel rather than as a self-propagating malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deployed Dropbear SSH on victim modems to maintain remote access over port 22.
During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems... Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks rely heavily on basic security failures. Threat actors have repeatedly exploited internet-facing programmable logic controllers (PLCs), weak or default passwords, shared operator accounts, poor IT/OT network segmentation, and exposed remote access tools.
The attacks rely heavily on basic security failures. Threat actors have repeatedly exploited internet-facing programmable logic controllers (PLCs), weak or default passwords, shared operator accounts, poor IT/OT network segmentation, and exposed remote access tools.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by the actors to maintain remote access on victim cellular modems over SSH.
A modified Dropbear SSH client used as a backdoor for persistent remote access (including use of a hardcoded backdoor password).
A modified Dropbear SSH client was deployed as a backdoor/persistence mechanism, including use of a hardcoded backdoor password for continued access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.