logo

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

ID: e9fdcf06-cad2-5418-9f82-8faf71d9ad7a

STIX ID: report--e9fdcf06-cad2-5418-9f82-8faf71d9ad7a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**PamDOORa** is a newly reported PAM-based Linux backdoor being sold on a Russian cybercrime forum that provides persistent SSH access via a special password/port pair, harvests credentials from users authenticating through the compromised PAM stack, and includes anti-forensic log tampering and operator-grade features (anti-debugging, network-aware triggers, and a builder pipeline); researchers note no observed real-world deployments but suspect it would be installed after an attacker already obtains root access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.