Suspicious SSH Reverse Tunnel via Renamed plink Utility on Triofox Host

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-23
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects renamed plink or putty binaries sihosts.exe and silcon.exe establishing a reverse SSH tunnel with the -R flag as observed after Triofox exploitation. Attackers proxy RDP over an outbound tunnel to a non standard port to maintain covert remote access.

Related detections9 linkedT1572 — drag to rearrange
Suspicious OpenSSH Reverse Tunnel Establishment via ssh.exe
Malicious Cloudflared Tunnel Established with Token
Malicious Reverse SSH Tunnel via Renamed PuTTY svchosts.exe (via process_creation)
Suspicious Cloudflare Tunnel Masquerading as conhost.exe During Medusa Operations (via process_creation)
Malicious NetSupport RAT Masquerading as systeminfo.exe
Suspicious Octo Tempest Remote Access and Tunneling Tooling (via process_creation)
Chisel Reverse Tunnel Tool Execution from Temporary Directory
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Suspicious MeshAgent Persistence via Scheduled Task MeshUserTask (via process_creation)
Suspicious SSH Reverse Tunnel via Renamed plink Utility on Triofox Host
Pivot detection · T1572 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.