logo

The Duality of the Pluggable Authentication Module (PAM)

ID: ad8f2775-3134-539f-b206-8daac091a079

STIX ID: report--ad8f2775-3134-539f-b206-8daac091a079

Feed Name: Group-IB Blog

Threat Score
55/100

Date Published: 2024-09-06

Date Updated: 2026-04-28

...
...

This report explains how Linux's Pluggable Authentication Module (PAM) framework—specifically the pam_exec module—can be abused to execute malicious scripts during authentication (e.g., SSH), enabling stealthy data exfiltration and persistent privileged access; Group-IB DFIR demonstrates the technique, highlights its forensic stealth, and recommends hardening and monitoring controls such as SELinux/AppArmor, auditd, file integrity tools, and restricted sudo/root access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.