Knowledge Centre
Home / News / Cyber Insurance News / Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks

Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks

Published on February 12, 2025. EST READ TIME: 2 minutes

Chinese Cyberspies Deploy New SSH Backdoor in Network Device Attacks

Evasive Panda, also known as DaggerFly, has been actively targeting network appliances since mid-November 2024 by injecting a novel malware into the SSH daemon (SSHD). This malware, designated “ELF/Sshdinjector.A!tr” by Fortinet’s FortiGuard Labs, allows attackers to hijack SSHD processes, facilitating persistent access and clandestine operations on compromised devices. Upon breaching a system, the attackers deploy a dropper component that verifies if the device is already infected and confirms it operates under root privileges. If these conditions are met, multiple binaries, including a malicious SSH library named “libssdh.so,” are installed. This library serves as the primary backdoor, enabling the attackers to execute a wide range of malicious activities. Evasive Panda has a history of sophisticated cyber-espionage campaigns, including recent supply chain attacks via ISPs in Asia and intelligence gathering from U.S. organizations. This latest development underscores the group’s evolving tactics and the ongoing threat posed by state-sponsored cyber actors.

Awards & Recognition
Image

BFSI Leadership Awards 2022 - Product Innovator of the Year (Optima Secure)

ETBFSI Excellence Awards 2021

FICCI Insurance Industry
Awards September 2021

ICAI Awards 2015-16

SKOCH Order-of-Merit

Best Customer Experience
Award of the Year

ICAI Awards 2014-15

Image

CMS Outstanding Affiliate World-Class Service Award 2015

Image

iAAA rating

Image

ISO Certification

Image

Best Insurance Company in Private Sector - General 2014

View all awards