Kobalos Malware
Summary
It appears that the main targets of the attack campaign involving the Kobalos Malware are high-performance computing (HPC) clusters, primarily located in Europe. The Kobalos Malware is capable of carrying out all of the generic threatening functions associated with a backdoor threat, which makes determining the real purpose of the campaign that much harder. In most cases, the Kobalos Malware is embedded in the OpenSSH server executable (sshd), and, to trigger the backdoor functionality, the inbound connection must come from a specific TCP source port. The hackers true goal is impossible to discern, as no other malware payloads have been dropped onto the infected machines, except a credentials collector that modifies the SSH client of the victims. The hackers appear to be improving this tool of their arsenal actively, though, and more recent versions now include some obfuscation and are able to exfiltrate the collected usernames and passwords.