Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

TunnesshClient

TunnesshClient is a PyInstaller backdoor observed as an additional payload in a large-scale malware distribution campaign that used more than 100 public GitHub repositories to spread the BoryptGrab information stealer via ZIP archives masquerading as legitimate software tools, utilities, and game cheats. In the reported infection chains, attackers used SEO-stuffed GitHub README files, fake download pages, DLL sideloading, VBS/PowerShell downloaders, and .NET loaders to deliver BoryptGrab and secondary payloads including TunnesshClient, Vidar variants, and the HeaconLoad Golang downloader. TunnesshClient establishes a reverse SSH tunnel to communicate with attackers and can act as a SOCKS5 proxy, providing remote access, file movement, and proxying through the infected host. It was specifically described as creating a reverse SSH tunnel enabling remote command execution, file movement, and proxying. The campaign infrastructure and Russian-language artifacts cited in the reporting suggest the operators may be of Russian origin. The malware was associated with infections targeting Windows systems through trojanized ZIP-delivered software and cheat lures hosted via GitHub-related infrastructure.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Command and Control

2 techniques
T1105Ingress Tool TransferEvidence1

The launcher downloads the BoryptGrab information stealer and may also retrieve other payloads, including Vidar variants... and a Golang downloader named HeaconLoad.

T1572Protocol TunnelingEvidence1

...TunnesshClient, which creates a reverse SSH tunnel to communicate with attackers... establishes a reverse SSH tunnel, allowing attackers to run commands, move files, and use the infected system as a proxy.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.