Group-Ib
Covert Linux XMRig Campaign Exploits PAM for Cryptomining
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In July 2026, a sophisticated cryptomining campaign utilizing XMRig was discovered, targeting Linux systems. The attackers exploited trusted access through third-party relationships, allowing them to infiltrate networks undetected. They weaponized the Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, enabling lateral movement while suppressing logging to avoid detection. The malware, a modified version of XMRig, was designed to run silently and avoid resource contention. This campaign poses a significant risk to organizations using Linux systems, as it can persist undetected through multiple user accounts. The full scope of affected systems is still being assessed, and organizations are urged to enhance their monitoring capabilities.
Key Points: • Attackers exploited trusted third-party access to infiltrate Linux environments. • The campaign utilizes PAM to obscure malicious activities and evade detection. • A modified XMRig miner is employed to mine Monero while minimizing resource alerts.