New PamDOORa Backdoor Attacking Linux Systems to Steal SSH Credentials
ID: 0c554c5b-b1c9-5054-ac97-75283223663b
STIX ID: report--0c554c5b-b1c9-5054-ac97-75283223663b
Feed Name: cybersecurityNews.com
PamDOORa is a newly reported Linux backdoor that hijacks the PAM authentication stack to silently capture SSH credentials, grant stealthy persistent access via a magic password and port, and perform anti-forensic cleanup of authentication logs; the malware (advertised on a cybercrime forum) includes IoCs such as a malicious pam_linux.so module, tn.sh script, /tmp credential files, use of port 1234, and modifications to /etc/pam.d/sshd, and researchers provide mitigation and monitoring recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
