Over 16,000 Servers Compromised via SSH Key Probing Method
An international research team from the Max Planck Institute and Delft University of Technology has developed a method to identify compromised servers on the internet by probing them with publicly available SSH keys that were previously linked to attacker operations. The technique, called Catch-22, leverages a subtle feature of the Secure Shell (SSH) protocol, detecting whether the server recognizes any of these known attacker keys, which signals a compromise. Over 16,000 compromised hosts were identified across various networks, including academic institutions, hosting providers, and enterprises. This method is efficient at scale, as it does not require completing the authentication process, reducing the potential for false positives. The study highlights a new use for an existing internet protocol, allowing defenders to detect compromises by observing attackers’ persistence tactics. The researchers worked with several organizations, including the Shadowserver Foundation, to notify affected entities and reduce the number of compromised servers. Their findings were presented at the USENIX Security Symposium 2025 and earned them prestigious awards, including the Internet Defense Prize.
