Pam Backdoor Targets Linux Systems to Steal SSH Credentials
ID: aa974072-bbc3-52aa-aea0-2820796a1b5b
STIX ID: report--aa974072-bbc3-52aa-aea0-2820796a1b5b
Feed Name: GBHackers
**PamDOORa / Pam backdoor:** Researchers report a technique that weaponizes PAM's pam_exec on Linux to run hidden scripts during SSH authentication, harvest usernames and environment variables (PAM_USER, PAM_RHOST, PAM_SERVICE), and exfiltrate data (e.g., via nc) while using the 'optional' control flag to avoid disrupting authentication and reduce logging; recommended mitigations include auditing /etc/pam.d/, restricting script execution, deploying file integrity monitoring, and enforcing SELinux/AppArmor policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
