PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs
ID: e6d58d25-2b58-5c9f-b679-311f94d0c996
STIX ID: report--e6d58d25-2b58-5c9f-b679-311f94d0c996
Feed Name: securityonline.info
Threat Score
A newly reported Linux backdoor called PamDOORa embeds into the PAM authentication stack to harvest credentials and maintain persistent SSH access via a ‘magic’ password and port; it includes anti-forensic log tampering and is being sold on a Russian cybercrime forum, creating a high-risk, stealthy post-exploitation threat that can bypass standard application-layer monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
