Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Posted on July 30, 2026 By CWS

A recent cryptomining campaign targeting Linux systems employs a sophisticated technique to remain undetected within compromised networks. By leveraging the Pluggable Authentication Modules (PAM) framework, attackers are able to discreetly mine Monero cryptocurrency without triggering standard security alerts.

Exploiting PAM for Stealth

The cyberattack was initiated in May 2026, when threat actors infiltrated a network via a trusted third-party connection. Once inside, they escalated their privileges to root level, allowing them extensive control over the system. However, rather than using this access openly, which would likely alert security teams, the attackers opted for a more covert method.

They manipulated the PAM framework to move between low-privileged accounts without needing passwords. This approach distributed their activity across lesser-monitored accounts, creating a forensic smokescreen that made detection difficult. Researchers from Group-IB identified this tactic, noting its ability to regenerate the botnet even after root access was cleaned.

Advanced Evasion Techniques

The payload used in this campaign is a modified version of the XMRig miner. It is designed to erase its binary from the disk while continuing to operate from memory, effectively evading antivirus detection. Additionally, the attackers disabled logging and altered authentication records on infected machines, further obscuring their presence.

These evasive strategies are typically seen in advanced persistent threats, where maintaining long-term access is crucial. The campaign’s reliance on trusted supply chain connections and memory-resident execution underscores its sophistication. Reviewing trends in recent ransomware analysis can provide insights into detecting similar tactics early.

Technical Details and Recommendations

The attackers exploited the pam_rootok policy within the PAM stack to impersonate users without entering passwords, facilitating the spread of malicious cronjobs. This persistence mechanism meant that merely addressing the root compromise would not eliminate the botnet.

To further evade detection, core logging services were halted, and authentication logs were tampered with, leaving minimal forensic evidence. This campaign highlights the necessity of monitoring PAM logs for unusual user activity, as rapid user transitions can indicate malicious behavior.

Security teams are advised to audit and restrict third-party access using zero trust principles, and to enhance visibility over logging services like rsyslog and auditd. Memory forensics is crucial for detecting implants that delete themselves, and understanding backdoors that exploit PAM can help identify potential threats.

Indicators of compromise include specific file artifacts and hashes related to the customized XMRig implant. Organizations should monitor these indicators to enhance their threat detection capabilities.

Strengthening defenses against such sophisticated attacks requires a combination of proactive monitoring, robust logging, and comprehensive forensic analysis.

Cyber Security News Tags:Botnet, Cryptomining, Cybersecurity, forensic analysis, Linux security, Malware, network security, PAM, threat detection, XMRig

Post navigation

Previous Post: Critical Flaw in Ruflo AI Exposes Systems to Attack
Next Post: State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks

Related Posts

ToxicPanda Android Banking Malware Infected 4500+ Devices to Steal Banking Credentials ToxicPanda Android Banking Malware Infected 4500+ Devices to Steal Banking Credentials Cyber Security News
MEA Faces Surge in Shipping Scams Exploiting Phishing Tactics MEA Faces Surge in Shipping Scams Exploiting Phishing Tactics Cyber Security News
North Korean Operatives Exploit LinkedIn for Remote Tech Jobs North Korean Operatives Exploit LinkedIn for Remote Tech Jobs Cyber Security News
GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware Cyber Security News
Microsoft Confirms Recent Windows 11 24H2/25H2 and Server 2025 Update Breaks RemoteApp Connections Microsoft Confirms Recent Windows 11 24H2/25H2 and Server 2025 Update Breaks RemoteApp Connections Cyber Security News
Threat Actor Installed EDR on Their Systems, Revealing Workflows and Tools Used Threat Actor Installed EDR on Their Systems, Revealing Workflows and Tools Used Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach
  • Silver Fox’s New BYOVD Attack Targets Japanese Industry
  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach
  • Silver Fox’s New BYOVD Attack Targets Japanese Industry
  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark