Tag: PAM Backdoor

New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft
News

New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft

Researchers studying cybersecurity have discovered a Linux backdoor known as Plague that had gone undetected for a year. According to Pierre-Henri Pezier, a researcher at Nextron Systems, the implant is designed as a malicious PAM (Pluggable Authentication Module), which allows attackers to covertly get around system authentication and obtain continuous SSH access. In Linux and UNIX-based systems, pluggable authentication modules are a group of shared libraries used to control user authentication to programs and services. A rogue PAM can facilitate the theft of user credentials, evade authentication checks, and evade detection by security measures because PAM modules are loaded into privileged authentication processes. According to the cybersecurity firm, since July 29, 2024, ...