Skip to main content

Worth reading: A Newly Discovered PAM-Based Backdoor for Linux

  • August 4, 2025
  • 4 comments
  • 137 views

SteveHeart
Forum|alt.badge.img+11

 

The company Nextron recently discovered a new and very stealthy Linux backdoor called “Plague” (Read the blog post). This malware is a malicious PAM (Pluggable Authentication Module) that lets attackers secretly bypass system authentication and keep SSH access for a long time. Although several samples have been uploaded to VirusTotal over the last year, no antivirus software detects them as malicious, and there are no public reports or detection rules for this threat (yet).

Plague hides deep in the system, survives updates, and barely leaves any traces, which makes it very hard to find with standard tools. This shows how dangerous backdoors targeting core Linux components like PAM can be.

To help others detect this threat, the blog post also contains a YARA rule. This case highlights why proactive detection with tools like YARA is important for catching hidden threats in Linux systems.

4 comments

Link State
Forum|alt.badge.img+12
  • Veeam Legend
  • August 4, 2025

thx for information 


JMeixner
Forum|alt.badge.img+18
  • On the path to Greatness
  • August 4, 2025

Interesting, never heard of this up to now.

Thank you, Steve. 👍🏼


coolsport00
Forum|alt.badge.img+22
  • Veeam Legend
  • August 4, 2025

Ugh..that’s a nasty one! Will take a look at that YARA rule. Appreciate the share Steve 👍🏻


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • August 4, 2025

Wow a Linux compromise thanks for sharing Steve. Will check that Yara rule out too.