Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-11
Updated
2026-09-11

ATT&CK techniques

Lateral Movement → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects use of the OpenSSH client to establish a reverse tunnel with the -R option forwarding traffic over port 443. The Chaos ransomware group abuses OpenSSH reverse tunneling to blend remote access and command-and-control into HTTPS traffic. Reverse tunnels over common web ports are used to evade network monitoring and maintain covert access.

Related detections9 linkedT1572 — drag to rearrange
Port Forwarding via SSH.EXE on Windows
Possible Plink Reverse Tunnel Command Line Execution
Chisel Reverse Tunnel Tool Execution from Temporary Directory
Malicious Anubis Ransomware Cloudflare Tunnel via cloudflared (via process_creation)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
OpenSSH Server Listening on Socket (via openssh)
Malicious RDP Tunneling (via rdp)
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Pivot detection · T1572 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.