18.6 C
Lisbon
Tuesday, May 12, 2026
HomeDefenceNew Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Cybersecurity researchers have disclosed a new Linux backdoor called PamDOORa, advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor known as darkworm. The backdoor operates as a Pluggable Authentication Module-based post-exploitation toolkit that enables persistent SSH access through a magic password and specific TCP port combination.

RELATED ARTICLES

Most Popular

Recent Comments