logo

New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials

ID: 0c554c5b-b1c9-5054-ac97-75283223663b

STIX ID: report--0c554c5b-b1c9-5054-ac97-75283223663b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

PamDOORa is a newly reported Linux backdoor that hijacks the PAM authentication stack to silently capture SSH credentials, grant stealthy persistent access via a magic password and port, and perform anti-forensic cleanup of authentication logs; the malware (advertised on a cybercrime forum) includes IoCs such as a malicious pam_linux.so module, tn.sh script, /tmp credential files, use of port 1234, and modifications to /etc/pam.d/sshd, and researchers provide mitigation and monitoring recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.