New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials
ID: e9fdcf06-cad2-5418-9f82-8faf71d9ad7a
STIX ID: report--e9fdcf06-cad2-5418-9f82-8faf71d9ad7a
Feed Name: The Hacker News
**PamDOORa** is a newly reported PAM-based Linux backdoor being sold on a Russian cybercrime forum that provides persistent SSH access via a special password/port pair, harvests credentials from users authenticating through the compromised PAM stack, and includes anti-forensic log tampering and operator-grade features (anti-debugging, network-aware triggers, and a builder pipeline); researchers note no observed real-world deployments but suspect it would be installed after an attacker already obtains root access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
