Skip to content
Covert Linux XMRig Campaign Exploits PAM for Cryptomining

Covert Linux XMRig Campaign Exploits PAM for Cryptomining

First seen 30 Jul 2026, 13:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • Attackers exploited trusted third-party access to infiltrate Linux environments.
  • The campaign utilizes PAM to obscure malicious activities and evade detection.
  • A modified XMRig miner is employed to mine Monero while minimizing resource alerts.

In July 2026, a sophisticated cryptomining campaign utilizing XMRig was discovered, targeting Linux systems. The attackers exploited trusted access through third-party relationships, allowing them to infiltrate networks undetected. They weaponized the Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, enabling lateral movement while suppressing logging to avoid detection. The malware, a modified version of XMRig, was designed to run silently and avoid resource contention. This campaign poses a significant risk to organizations using Linux systems, as it can persist undetected through multiple user accounts. The full scope of affected systems is still being assessed, and organizations are urged to enhance their monitoring capabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 53d ago How this analysis works

Timeline

2026-05-01
Campaign initiation
Threat actors leveraged trusted relationships to gain initial access to targeted Linux systems.
Group-IB
2026-07-30
Campaign disclosure
Group-IB published findings on the XMRig campaign, detailing its stealth techniques and exploitation methods.
Group-IB
2026-07-30
Media coverage
Cybersecuritynews reported on the campaign, highlighting the use of PAM for hiding activities.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track XMRig in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed