ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft

Threat Score:
57
The Hacker News
23 hours ago
Part of cluster #1587

Overview

Cybersecurity researchers have flagged a previously undocumented Linux backdoor dubbedPlaguethat has managed to evade detection for a year. "The implant is built as a maliciousPAM(Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access," Nextron Systems researcher Pierre-Henri Peziersaid. Pluggable Authentication Modules refers to a suite of shared libraries used to manage user authentication to applications and services in Lin...

Continue Reading on Original Site

Related Articles

5 articles
1

Cyber Crisis Unfolding: PH ransomware cases double, as reported by Viettel Cyber Security - Manila Standard

News • 2 hours ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
82
Read more
2

Semperis 2025 Ransomware Study Highlights Persistence of Cyber Threats and Evolving Tactics - Israel Defense

News • 7 hours ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
82
Read more
3

Traditional backup strategies are no longer sufficient to guarantee business continuity. Sophisticated cyberattacks, particularly ransomware, have evolved beyond merely encrypting or deleting primary data. Attackers now meticulously target the very systems d - LinkedIn

News • 14 hours ago

EnglishUnited States Deutsch English Español Français Italiano العربية All languages Afrikaans azərbaycan bosanski català Čeština Cymraeg Dansk Deutsch eesti EnglishUnited Kingdom EspañolEspaña EspañolLatinoamérica euskara Filipino FrançaisCanada FrançaisFrance Gaeilge galego Hrvatski Indonesia isiZulu íslenska Italiano Kiswahili latviešu lietuvių magyar Melayu Nederlands norsk o‘zbek polski PortuguêsBrasil PortuguêsPortugal română shqip Slovenčina slovenščina srpski (latinica) Suomi Svenska Tiế

Score
74
Read more
4

Security Affairs newsletter Round 535 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs • 3 hours ago

A new round of the weekly Security Affairs has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs , including the international press. New Linux backdoor Plague bypasses auth via malicious PAM module China Presses Nvidia Over Alleged Backdoors […]

Score
73
Read more
5

New Linux backdoor Plague bypasses auth via malicious PAM module

Security Affairs • 13 hours ago

A stealthy Linux backdoor named Plague, hidden as a malicious PAM module, allows attackers to bypass auth and maintain persistent SSH access. Nextron Systems researchers discovered a new stealthy Linux backdoor called Plague, hidden as a malicious PAM (Pluggable Authentication Module) module. It silently bypasses authentication and grants persistent SSH access. A Pluggable Authentication Module […]

Score
73
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

FILE PATH
/dev/null to prevent shell command logging, in order otherwise avoid leaving an audit trail. "Plague integrates deeply into the authentication stack, survives system updates, and leaves almost no forensic traces," Pezier noted. "Combined with layered obfuscation and environment tampering, this makes it exceptionally hard to detect using traditional tools."
ATTACK TYPES
Authentication Bypass
Credential Theft
Malicious PAM Backdoor
SSH Access
PLATFORMS
Linux
RANSOMWARE
Unknown
silent
MALWARE
Dark Shades
Plague
Rogue
MITRE ATT&CK
T1027
T1059.001
T1059.004
T1068
T1070.001
VULNERABILITIES
Authentication Bypass
Backdoor
Malware
COMPANIES
Nextron Systems
INDUSTRIES
Cybersecurity
ARTICLE INFORMATION
Article #7236
Published 23 hours ago
The Hacker News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration