CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Operation SkyCloak targets defense sectors with Tor-enabled OpenSSH backdoor

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Operation SkyCloak is an ongoing cyber espionage campaign targeting defense sectors in Russia and Belarus. The attack uses phishing emails with weaponized attachments to deploy a persistent backdoor on compromised hosts. The backdoor leverages OpenSSH and a customized Tor hidden service for command-and-control (C2) communications. The campaign employs sophisticated anti-analysis techniques and environmental checks to evade detection. It establishes persistence through scheduled tasks and exfiltrates system information via a .onion URL. The threat actors behind the campaign remain unidentified, but the activity aligns with Eastern European-linked espionage targeting defense and government sectors.

Timeline

  1. 04.11.2025 12:49 1 articles · 6d ago

    Operation SkyCloak targets defense sectors with Tor-enabled OpenSSH backdoor

    Operation SkyCloak is an ongoing cyber espionage campaign targeting defense sectors in Russia and Belarus. The attack uses phishing emails with weaponized attachments to deploy a persistent backdoor on compromised hosts. The backdoor leverages OpenSSH and a customized Tor hidden service for command-and-control (C2) communications. The campaign employs sophisticated anti-analysis techniques and environmental checks to evade detection. It establishes persistence through scheduled tasks and exfiltrates system information via a .onion URL. The threat actors behind the campaign remain unidentified, but the activity aligns with Eastern European-linked espionage targeting defense and government sectors.

    Show sources

Information Snippets