logo

New Linux backdoor Plague bypasses auth via malicious PAM module

ID: 968a4a40-314d-5bfd-a1fe-055ff8236455

STIX ID: report--968a4a40-314d-5bfd-a1fe-055ff8236455

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-08-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A newly reported Linux backdoor called Plague is implemented as a malicious PAM module that silently bypasses authentication and grants persistent SSH access. The malware employs progressively more complex string obfuscation (from XOR to KSA/PRGA-like routines and a DRBG layer), anti-debugging checks, a static backdoor password, and session sanitization to evade detection and analysis; researchers used custom dynamic emulation to extract hidden strings. Attribution is unknown, and while multiple samples have appeared on VirusTotal, they were often flagged as non-malicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.