Skip to content

Hide Navigation Hide TOC

Injected Code — Unauthorized Remote Access (SSH Key Backdoor / Tunnel / Port Forward) - ATR-2026-01899 (b2286a9e-9cf4-5cf7-b28c-bd75c0cd95d7)

Detects injected code that establishes a persistent or interactive backdoor: appending a remote-fetched key to ~/.ssh/authorized_keys, opening an interactive SSH local-forward tunnel via pexpect, or building a socket port-forward bridge from a local listener to a remote host.

Cluster A Galaxy A Cluster B Galaxy B Level
Injected Code — Unauthorized Remote Access (SSH Key Backdoor / Tunnel / Port Forward) - ATR-2026-01899 (b2286a9e-9cf4-5cf7-b28c-bd75c0cd95d7) Agent Threat Rules LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern 1
Injected Code — Unauthorized Remote Access (SSH Key Backdoor / Tunnel / Port Forward) - ATR-2026-01899 (b2286a9e-9cf4-5cf7-b28c-bd75c0cd95d7) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1