Reverse SSH Tunnel for RDP Proxying (Bumblebee/AdaptixC2/Akira)
Detects the execution of the SSH client (ssh.exe) with remote port forwarding arguments (-R). This technique is commonly used by adversaries to establish a reverse SSH tunnel, allowing them to proxy Remote Desktop Protocol (RDP) traffic from an internal victim machine to an external attacker-controlled server, effectively bypassing perimeter firewall restrictions. This behavior has been observed in various ransomware and C2 campaigns, including Bumblebee and Akira.
Sigma

