Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

0
High
Analysis
Published: 08/06/2026 (08/06/2026, 00:15:40 UTC)
Source: SANS ISC Handlers Diary

Description

This report documents an automated SSH brute-force campaign observed via a Cowrie honeypot, where attackers use compromised credentials to gain access and establish persistent backdoors within 22 seconds. The attacker injects SSH keys, changes root passwords, clears host-based restrictions, and performs reconnaissance immediately after login. The campaign is ongoing, involves coordinated scanning from multiple IPs including a known malicious subnet, and leverages weak or default credentials. The rapid automation leaves no time for human intervention once authentication succeeds. Defenders are advised to disable password authentication, enforce strong passwords, implement rate limiting, restrict SSH access, and monitor logs for rapid post-login command sequences.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 00:26:24 UTC

Technical Analysis

On May 23, 2026, an automated actor successfully authenticated to a Cowrie SSH honeypot using weak, commonly leaked credentials. Within 22 seconds, the actor injected a malicious SSH key, changed the root password, cleared /etc/hosts.deny, and executed system reconnaissance commands. This behavior was repeated consistently across multiple sessions and IPs, indicating a scripted automated attack rather than manual exploitation. The campaign, identified as part of the ongoing 'mdrfckr' SSH scanning operation, involves coordinated scanning from multiple IPs within the same subnet and uses a broad credential wordlist including gaming server defaults. Threat intelligence sources confirm the malicious reputation of involved IPs. The attack leverages no zero-days or novel exploits but relies on weak SSH credentials and lack of rate limiting. MITRE ATT&CK techniques observed include valid account use, account manipulation, command execution, and defense impairment.

Potential Impact

Successful authentication with weak or leaked credentials allows attackers to establish persistent backdoor access rapidly, lock out legitimate administrators by changing passwords, remove host-based access restrictions, and perform system reconnaissance. The automation and speed of the attack mean that human detection and response are unlikely to prevent compromise once authentication occurs. The campaign is widespread and persistent, targeting any internet-exposed SSH service with weak credentials, increasing the risk of unauthorized access and potential system takeover.

Defensive Guidance

The vendor advisory equivalent here recommends multiple mitigations: disable SSH password authentication and require public key authentication only to prevent credential stuffing attacks; enforce strong password policies to eliminate weak credentials; implement rate limiting and account lockout mechanisms (e.g., fail2ban) to reduce brute-force success; restrict SSH access to trusted IP ranges or VPNs to limit exposure; and continuously monitor authentication logs for rapid post-login command execution patterns indicative of automated attacks. These mitigations effectively prevent or detect this automated campaign. No patch is applicable as this is an operational security issue rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://isc.sans.edu/diary/rss/33220","fetched":true,"fetchedAt":"2026-08-06T00:26:13.416Z","wordCount":1821}

Threat ID: 6a73d4a5bf8831d539b412b2

Added to database: 08/06/2026, 00:26:13 UTC

Last enriched: 08/06/2026, 00:26:24 UTC

Last updated: 08/06/2026, 03:02:49 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses