🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution
Continuing our story about the activities of the ExCobalt group and its new tool — the Puma rootkit, presented at the PHDays cyberfestival, we will take a closer look at one of its most sophisticated and dangerous techniques — the hidden modification of the authorized_keys file.
⚙️ How it works
The LKM rootkit intercepts the open and openat system calls executed by the ssh process, monitoring accesses to the authorized_keys file located in the ~/.ssh/ directory. This file is the primary mechanism for passwordless authentication in OpenSSH. If a client presents a private key corresponding to one of the public keys in this file, the server considers the user authentic, does not request a password, and grants system access.
When the ssh process attempts to read this file, the rootkit modifies the content returned by the system on the fly: the public key stored in the rootkit’s memory is appended to the original data. The file itself remains untouched: the substitution is performed exclusively in kernel memory at the time of the read call.
Thus, in a typical attack scenario:
1. The attacker initiates an SSH connection and attempts to authenticate using their own private key.
2. The sshd process on the machine reads the keys from the authorized_keys file.
3. The rootkit stealthily appends its own key to the returned file content.
4. The sshd process perceives the injected key as legitimate and grants the attacker access without requesting a password.
5. As a result, the attacker gains full interactive access to the compromised system under any user’s identity and the ability to execute arbitrary commands.
The danger of this technique is high because, until the rootkit is unloaded from system memory, even a complete password change or disabling password authentication entirely will not eliminate the threat, and the file content on disk remains unchanged, ensuring a high degree of stealth for this technique. The situation is especially dangerous when the key is injected into the authorized_keys file of a user with root privileges. In this case, attackers obtain unlimited privileges and absolute control over the compromised system.
🔎 How to quickly detect this attack
To detect the hidden modification of the authorized_keys file, the following method can be used: compare the file content obtained by reading it with the original /bin/cat utility against the content obtained by reading it with the same utility, but renamed to ssh. The reason is that Puma relies on the process name before modifying the content of the authorized_keys file, and if there is a difference in the outputs, it can be confidently stated that a rootkit is present in the system.
To automate such detection, we suggest using a script, which we have left in the comments.
If discrepancies are found in the file reading results when running the script, this is an unambiguous sign of system compromise and requires immediate response measures:
• restricting SSH access;
• capturing a memory dump;
• contacting information security incident response specialists.
#TI #Detect #APT #Malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



