TunnesshClient
TunnesshClient is a PyInstaller backdoor observed as an additional payload in a large-scale malware distribution campaign that used more than 100 public GitHub repositories to spread the BoryptGrab information stealer via ZIP archives masquerading as legitimate software tools, utilities, and game cheats. In the reported infection chains, attackers used SEO-stuffed GitHub README files, fake download pages, DLL sideloading, VBS/PowerShell downloaders, and .NET loaders to deliver BoryptGrab and secondary payloads including TunnesshClient, Vidar variants, and the HeaconLoad Golang downloader. TunnesshClient establishes a reverse SSH tunnel to communicate with attackers and can act as a SOCKS5 proxy, providing remote access, file movement, and proxying through the infected host. It was specifically described as creating a reverse SSH tunnel enabling remote command execution, file movement, and proxying. The campaign infrastructure and Russian-language artifacts cited in the reporting suggest the operators may be of Russian origin. The malware was associated with infections targeting Windows systems through trojanized ZIP-delivered software and cheat lures hosted via GitHub-related infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor enabling reverse SSH tunneling and SOCKS5 proxying for attacker communications and pivoting.
PyInstaller-based backdoor that establishes a reverse SSH tunnel, enabling remote command execution, file movement, and use of the victim host as a proxy.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.