Plague PAM-Based Backdoor for Linux (Campaign)
ID: 8b20b279-eb1e-55e7-a208-262d0560afe8
STIX ID: report--8b20b279-eb1e-55e7-a208-262d0560afe8
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-08-04
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Plague is a PAM-based Linux backdoor that impersonates legitimate shared libraries (for example, `libselinux.so.8`) to hook into the authentication stack and grant stealthy, persistent SSH access using hardcoded passwords. The implant employs layered obfuscation (XOR, custom KSA/PRGA-like routines, DRBG), anti-debug checks, and clears SSH-related environment variables and shell history to evade detection and leave minimal forensic traces; samples date back to mid-2024, indicating active development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
