Covert Linux XMRig Campaign Exploits PAM for Cryptomining

Covert Linux XMRig Campaign Exploits PAM for Cryptomining

First seen 30 Jul 2026, 13:40 UTC Group-IbCybersecuritynews 77% similarity 69.5

Article Content

Browse articles
ThreatCluster

In July 2026, a sophisticated cryptomining campaign utilizing XMRig was discovered, targeting Linux systems. The attackers exploited trusted access through third-party relationships, allowing them to infiltrate networks undetected. They weaponized the Linux Pluggable Authentication Modules (PAM) to create a forensic smokescreen, enabling lateral movement while suppressing logging to avoid detection. The malware, a modified version of XMRig, was designed to run silently and avoid resource contention. This campaign poses a significant risk to organizations using Linux systems, as it can persist undetected through multiple user accounts. The full scope of affected systems is still being assessed, and organizations are urged to enhance their monitoring capabilities.

Key Points: • Attackers exploited trusted third-party access to infiltrate Linux environments. • The campaign utilizes PAM to obscure malicious activities and evade detection. • A modified XMRig miner is employed to mine Monero while minimizing resource alerts.

ThreatCluster AI How this analysis works

Timeline

2026-05-01
Campaign initiation
Threat actors leveraged trusted relationships to gain initial access to targeted Linux systems.
Group-IB
2026-07-30
Campaign disclosure
Group-IB published findings on the XMRig campaign, detailing its stealth techniques and exploitation methods.
Group-IB
2026-07-30
Media coverage
Cybersecuritynews reported on the campaign, highlighting the use of PAM for hiding activities.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story