logo

Understanding Credential Harvesting via PAM: A Real-World Threat

ID: 20baef0b-8ec8-5000-81af-f1c2f14b04d6

STIX ID: report--20baef0b-8ec8-5000-81af-f1c2f14b04d6

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2025-05-08

Date Updated: 2026-04-28

...
...

This blog explains how PAM modules (e.g., pam_unix.so) can be maliciously modified to log or exfiltrate plaintext credentials (MITRE ATT&CK T1556.003), provides a concrete code example and test evidence showing credentials written to system logs, cites real-world abuse by UNC1945 and UNC2891, and recommends mitigations such as disabling password-based SSH authentication, adopting key-based SSH, auditing PAM binaries, and deploying file-integrity monitoring and centralized logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.