{"id":855,"date":"2026-05-08T11:41:21","date_gmt":"2026-05-08T11:41:21","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=855"},"modified":"2026-05-08T11:41:21","modified_gmt":"2026-05-08T11:41:21","slug":"new-linux-pamdoora-backdoor-uses-pam-modules-to-steal-ssh-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=855","title":{"rendered":"New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 08, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Threat Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEixNgyNI9ObZi3Il87CVXhEWyWgcK-O1IKhQKRs7NPrNVqTMBZRw7AZpmbk5RdsPxNPmO9IyXaq6QzYBN691HBgfE8HpwnyJuE4-vaCAwHPpb6UfeSRcrMI-GRjcX53cELs31s7ps6YkGx5bAAB67w4m9GQ7ZVWjSdnaPOFczjHlsS3967ZvBh-4ZvTBWEJ\/s1700-e365\/linux-pam.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new Linux backdoor named <strong>PamDOORa<\/strong> that&#8217;s being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called \u00abdarkworm.\u00bb<\/p>\n<p>The backdoor is designed as a Pluggable Authentication Module (<a href=\"https:\/\/www.redhat.com\/en\/blog\/pluggable-authentication-modules-pam\">PAM<\/a>)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP port combination. It&#8217;s also capable of harvesting credentials from all legitimate users who authenticate through the compromised system.<\/p>\n<p>\u00abThe tool, called PamDOORa, is a new PAM-based backdoor, designed to serve as a post-exploitation backdoor, enabling authentication to servers via OpenSSH,\u00bb Flare.io researcher Assaf Morag <a href=\"https:\/\/flare.io\/learn\/resources\/blog\/pamdoora-new-linux-pam-based-backdoor-sale-dark-web\">said<\/a> in a technical report. \u00abAllegedly this would remain persistent on Linux systems (x86_64).\u00bb<\/p>\n<p>PamDOORa is the second Linux backdoor targeting the PAM stack after Plague. PAM is a security framework in Unix\/Linux operating systems that grants system administrators the ability to incorporate multiple authentication mechanisms or update them (e.g., switching from passwords to biometrics) into an existing system through the use of pluggable modules without the need for rewriting existing applications.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Because PAM modules typically run with <a href=\"https:\/\/www.cyberark.com\/resources\/endpoint-privilege-security\/plague-malware-exploits-pluggable-authentication-module-to-breach-linux-systems\">root privileges<\/a>, a compromised, misconfigured, or malicious module can introduce significant security risks and open the door to credential harvesting and unauthorized access.<\/p>\n<p>\u00abDespite its strengths, the Pluggable Authentication Module&#8217;s (PAM) modularity introduces risks, as malicious modifications to PAM modules can create backdoors or steal user credentials, especially since PAM does not store passwords but transmits values in plaintext,\u00bb Group-IB <a href=\"https:\/\/www.group-ib.com\/blog\/pluggable-authentication-module\/\">noted<\/a> in September 2024.<\/p>\n<p>\u00abThe pam_exec module, which allows the execution of external commands, can be exploited by attackers to gain unauthorized access or establish persistent control by injecting malicious scripts into PAM configuration files.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5BOXKdu5522ta-1c7W3cJ_fo1y2eyvW_sZdnM3GAmK-aMGxsjl9SOc0qet7jxLeHrKzTjdSx2XdKlANomTIJhyphenhyphenpdHs91SusWt67CV4zAGpLfhH6GfdfQEPUZ7FoRTA3tAaYWKwq91gB93hbL77oQqr0buFJnljy9Q901n1cdiQMQRH7yQhM4ujk4ahKB4\/s1700-e365\/pam.jpeg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5BOXKdu5522ta-1c7W3cJ_fo1y2eyvW_sZdnM3GAmK-aMGxsjl9SOc0qet7jxLeHrKzTjdSx2XdKlANomTIJhyphenhyphenpdHs91SusWt67CV4zAGpLfhH6GfdfQEPUZ7FoRTA3tAaYWKwq91gB93hbL77oQqr0buFJnljy9Q901n1cdiQMQRH7yQhM4ujk4ahKB4\/s1700-e365\/pam.jpeg\" alt=\"\" border=\"0\" data-original-height=\"614\" data-original-width=\"1030\"\/><\/a><\/div>\n<p>The Singaporean security vendor also detailed how it&#8217;s possible to manipulate PAM configuration for SSH authentication to execute a script via pam_exec, effectively allowing a bad actor to obtain a privileged shell on a host and facilitate stealthy persistence.<\/p>\n<p>The latest findings from Flare.io show that PamDOORa, besides enabling credential theft, incorporates anti-forensic capabilities to methodically tamper with authentication logs to erase traces of malicious activity.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Although there is no evidence that the malware has been put to use in real-world attacks, infection chains distributing the malware are likely to involve the adversary first obtaining root access to the host through some other means and deploying the PamDOORa PAM module to capture credentials and establish persistent access over SSH.<\/p>\n<p>After an initial asking price of $1,600 on March 17, 2026, the \u00abdarkworm\u00bb persona has since reduced it by almost 50% to $900 as of April 9, indicating either a lack of buyer interest or an intent to accelerate a sale.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihDVYXue_Q5wypjsWxqc5xrBRNMKtSy-yjNlfoSIDroScODB7xn3XNMWj5-OJgkBKiixywyupxpotgwylU2iqkTJf7nE72vyDQnyDTQPwtJFQf9SVCBRXw4e3F0iF4fPYCAoPYEo4KE7rr5jUTacm2RLA890S1pb3IwRSBIJt-hvIkurGcmFFhNg9_8k_I\/s1700-e365\/pam-1.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihDVYXue_Q5wypjsWxqc5xrBRNMKtSy-yjNlfoSIDroScODB7xn3XNMWj5-OJgkBKiixywyupxpotgwylU2iqkTJf7nE72vyDQnyDTQPwtJFQf9SVCBRXw4e3F0iF4fPYCAoPYEo4KE7rr5jUTacm2RLA890S1pb3IwRSBIJt-hvIkurGcmFFhNg9_8k_I\/s1700-e365\/pam-1.png\" alt=\"\" border=\"0\" data-original-height=\"833\" data-original-width=\"1680\"\/><\/a><\/div>\n<p>\u00abPamDOORa represents an evolution over existing open-source PAM backdoors,\u00bb Morag explained. \u00abWhile the individual techniques (PAM hooks, credential capture, log tampering) are well-documented, the integration into a cohesive, modular implant with anti-debugging, network-aware triggers, and a builder pipeline places it closer to operator-grade tooling than the crude proof-of-concept scripts found in most public repositories.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 08, 2026Malware \/ Threat Intelligence Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that&#8217;s being advertised on the Rehub Russian cybercrime forum for $1,600&hellip;<\/p>\n","protected":false},"author":1,"featured_media":856,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,446,181,1491,1579,1578,1580,571],"class_list":["post-855","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-credentials","tag-linux","tag-modules","tag-pam","tag-pamdoora","tag-ssh","tag-steal"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=855"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/855\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/856"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}