logo

The “P” in PAM is for Persistence: Linux Persistence Technique

ID: 63823308-6907-5bdb-86c3-f823dccbb084

STIX ID: report--63823308-6907-5bdb-86c3-f823dccbb084

Feed Name: Black Hills Infosec Blog

Threat Score
55/100

Date Published: 2026-03-04

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates a proof-of-concept Linux persistence technique using a malicious Pluggable Authentication Modules (PAM) replacement called 'PAM Skeleton Key' that creates a universal login password and exfiltrates cleartext credentials to a webhook; it includes installation, use, and reversal steps and notes root access is required to install the backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.