Researchers studying cybersecurity have discovered a Linux backdoor known as Plague that had gone undetected for a year.
According to Pierre-Henri Pezier, a researcher at Nextron Systems, the implant is designed as a malicious PAM (Pluggable Authentication Module), which allows attackers to covertly get around system authentication and obtain continuous SSH access.
In Linux and UNIX-based systems, pluggable authentication modules are a group of shared libraries used to control user authentication to programs and services.
A rogue PAM can facilitate the theft of user credentials, evade authentication checks, and evade detection by security measures because PAM modules are loaded into privileged authentication processes.
According to the cybersecurity firm, since July 29, 2024, several Plague artifacts have been posted to VirusTotal New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
