Understanding Credential Harvesting via PAM: A Real-World Threat
ID: 20baef0b-8ec8-5000-81af-f1c2f14b04d6
STIX ID: report--20baef0b-8ec8-5000-81af-f1c2f14b04d6
Feed Name: Group-IB Blog
Threat Score
This blog explains how PAM modules (e.g., pam_unix.so) can be maliciously modified to log or exfiltrate plaintext credentials (MITRE ATT&CK T1556.003), provides a concrete code example and test evidence showing credentials written to system logs, cites real-world abuse by UNC1945 and UNC2891, and recommends mitigations such as disabling password-based SSH authentication, adopting key-based SSH, auditing PAM binaries, and deploying file-integrity monitoring and centralized logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
