By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft
Tech News

New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft

By Viral Trending Content 2 Min Read
Share
SHARE

Aug 02, 2025Ravie LakshmananThreat Detection / SSH Security

Linux Malware

Cybersecurity researchers have flagged a previously undocumented Linux backdoor dubbed Plague that has managed to evade detection for a year.

“The implant is built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access,” Nextron Systems researcher Pierre-Henri Pezier said.

Pluggable Authentication Modules refers to a suite of shared libraries used to manage user authentication to applications and services in Linux and UNIX-based systems.

Given that PAM modules are loaded into privileged authentication processes, a rogue PAM can enable theft of user credentials, bypass authentication checks, and remain undetected by security tools.

Identity Security Risk Assessment

The cybersecurity company said it uncovered multiple Plague artifacts uploaded to VirusTotal since July 29, 2024, with none of them detected by antimalware engines as malicious. What’s more, the presence of several samples signals active development of the malware by the unknown threat actors behind it.

Plague boasts of four prominent features: Static credentials to allow covert access, resist analysis and reverse engineering using anti-debugging and string obfuscation; and enhanced stealth by erasing evidence of an SSH session.

This, in turn, is accomplished by unsetting environment variables such as SSH_CONNECTION and SSH_CLIENT using unsetenv, and redirecting HISTFILE to /dev/null to prevent shell command logging, in order otherwise avoid leaving an audit trail.

“Plague integrates deeply into the authentication stack, survives system updates, and leaves almost no forensic traces,” Pezier noted. “Combined with layered obfuscation and environment tampering, this makes it exceptionally hard to detect using traditional tools.”

You Might Also Like

Hybrid work crucial for more than 50pc of employees, finds IrishJobs

Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents

ICE Asks Companies About ‘Ad Tech and Big Data’ Tools It Could Use in Investigations

Asus ROG Phone & Zenfone Smartphones No Longer Being Made

Siri’s Transformation in iOS 27: Apple’s AI Chatbot Explained

TAGGED: Antivirus, Credential Theft, Cyber Security, cyber Threat Intelligence, Cybersecurity, Internet, Linux, Malware, Nextron Systems, reverse engineering, ssh security, threat detection
Share This Article
Facebook Twitter Copy Link
Previous Article 11 Best Coolers WIRED Tested for Every Budget, Any Situation (2025)
Next Article SharpLink buys another $54M in ETH, now holds $1.65B worth of Ether
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

In the case of the Federal Reserve, Supreme Court appears to carve out a murky exception
Business
Today in History: January 25, Charles Manson convicted of murder, conspiracy
World News
Calls grow for ICE to leave Minnesota after latest shooting of citizen
World News
Colombia’s second-largest pension fund to offer Bitcoin exposure
Crypto
The Super Mario Galaxy Movie Direct Set for January 25th
Gaming News
European airlines suspend flights to Dubai over Middle-East tensions
World News
Q3 earnings, Fed rate decision, Budget to steer Dalal Street this week
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

In the case of the Federal Reserve, Supreme Court appears to carve out a murky exception

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
In the case of the Federal Reserve, Supreme Court appears to carve out a murky exception
January 25, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?