Skip to content

Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

Gbhackers Mayura Kathir July 30, 2026

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tracked as part of the V25 (Generation 26) campaign family, demonstrates a mature blend of supply chain abuse, PAM weaponization, and […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)