The Containment Era is here. →Explore

Executive Summary

In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration.

The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.

Why This Matters Now

The deployment of Tor-enabled OpenSSH backdoors targeting defense sectors shows adversaries are escalating efforts to evade traditional detection and persist within segmented environments. As covert malware tactics become more common, organizations must urgently bolster segmentation, encrypted traffic inspection, and anomaly detection to minimize risk of advanced, persistent attacks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The backdoor leveraged OpenSSH within a Tor hidden service using obfs4, enabling encrypted, anonymized communication that evaded traditional monitoring and network controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust network segmentation, east-west traffic controls, egress policy enforcement, and deep threat detection would have impeded the attacker’s ability to gain lateral movement, establish covert C2, and exfiltrate data by limiting privilege scope, monitoring unusual flows, and enforcing granular policies across workloads and cloud estates.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Early detection of suspicious activity or malware execution.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited blast radius for privilege escalation attempts.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detection and enforcement prevent unauthorized east-west pivots.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound C2 channels are detected and/or blocked.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Visibility for encrypted data flows and detection of anomalous exfiltration.

Impact (Mitigations)

Unified observability highlights persistent threats throughout cloud environments.

Impact at a Glance

Affected Business Functions

  • Network Security
  • Data Integrity
  • Confidential Communications
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive defense-related information due to unauthorized remote access.

Recommended Actions

  • Deploy zero trust segmentation and east-west traffic controls to reduce the lateral movement surface for attackers.
  • Enforce egress filtering and outbound policy to block C2 communications, especially to Tor/obfuscated endpoints.
  • Leverage runtime threat detection and anomaly response systems for rapid identification of suspicious behavior and persistence mechanisms.
  • Apply microsegmentation and least privilege principles to data and workloads to ensure compromise is contained.
  • Centralize multicloud visibility and control to enable rapid detection, containment, and remediation of backdoor and C2 activity in hybrid environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image