New Undectable Plague Malware Attacking Linux Servers to Gain Persistent SSH Access
ID: 3d345de2-33c8-5af6-a21b-878abcb3b375
STIX ID: report--3d345de2-33c8-5af6-a21b-878abcb3b375
Feed Name: cybersecurityNews.com
Threat Score
**Plague** is a sophisticated Linux backdoor that subverts PAM authentication to provide persistent, covert SSH access, using evolving string obfuscation, anti-debug checks, hardcoded backdoor credentials, and session sanitization to evade detection; multiple samples compiled across 2024–2025 and submitted to VirusTotal exhibited 0/66 AV detections, and the report includes SHA-256 IoCs and mitigation recommendations to audit PAM modules and monitor authentication subsystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
