logo

PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs

ID: e6d58d25-2b58-5c9f-b679-311f94d0c996

STIX ID: report--e6d58d25-2b58-5c9f-b679-311f94d0c996

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

A newly reported Linux backdoor called PamDOORa embeds into the PAM authentication stack to harvest credentials and maintain persistent SSH access via a ‘magic’ password and port; it includes anti-forensic log tampering and is being sold on a Russian cybercrime forum, creating a high-risk, stealthy post-exploitation threat that can bypass standard application-layer monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.