New Linux backdoor Plague bypasses auth via malicious PAM module
ID: 968a4a40-314d-5bfd-a1fe-055ff8236455
STIX ID: report--968a4a40-314d-5bfd-a1fe-055ff8236455
Feed Name: Security Affairs
A newly reported Linux backdoor called Plague is implemented as a malicious PAM module that silently bypasses authentication and grants persistent SSH access. The malware employs progressively more complex string obfuscation (from XOR to KSA/PRGA-like routines and a DRBG layer), anti-debugging checks, a static backdoor password, and session sanitization to evade detection and analysis; researchers used custom dynamic emulation to extract hidden strings. Attribution is unknown, and while multiple samples have appeared on VirusTotal, they were often flagged as non-malicious.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
