Group-Ib Covert Linux XMRig Campaign Exploits PAM for Cryptomining
Article Content
- •Attackers exploited trusted third-party access to infiltrate Linux environments.
- •The campaign utilizes PAM to obscure malicious activities and evade detection.
- •A modified XMRig miner is employed to mine Monero while minimizing resource alerts.
In July 2026, a sophisticated cryptomining campaign utilizing XMRig was discovered, targeting Linux systems. The attackers exploited trusted access through third-party relationships, allowing them to infiltrate networks undetected. They weaponized the Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, enabling lateral movement while suppressing logging to avoid detection. The malware, a modified version of XMRig, was designed to run silently and avoid resource contention. This campaign poses a significant risk to organizations using Linux systems, as it can persist undetected through multiple user accounts. The full scope of affected systems is still being assessed, and organizations are urged to enhance their monitoring capabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track XMRig in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Human Attacker Exploits Marimo RCE at Machine Speed A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven…