logo

Pam Backdoor Targets Linux Systems to Steal SSH Credentials

ID: aa974072-bbc3-52aa-aea0-2820796a1b5b

STIX ID: report--aa974072-bbc3-52aa-aea0-2820796a1b5b

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

**PamDOORa / Pam backdoor:** Researchers report a technique that weaponizes PAM's pam_exec on Linux to run hidden scripts during SSH authentication, harvest usernames and environment variables (PAM_USER, PAM_RHOST, PAM_SERVICE), and exfiltrate data (e.g., via nc) while using the 'optional' control flag to avoid disrupting authentication and reduce logging; recommended mitigations include auditing /etc/pam.d/, restricting script execution, deploying file integrity monitoring, and enforcing SELinux/AppArmor policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.