Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Posted on July 30, 2026 By CWS

A recent cryptomining campaign targeting Linux systems employs a sophisticated technique to remain undetected within compromised networks. By leveraging the Pluggable Authentication Modules (PAM) framework, attackers are able to discreetly mine Monero cryptocurrency without triggering standard security alerts.

Exploiting PAM for Stealth

The cyberattack was initiated in May 2026, when threat actors infiltrated a network via a trusted third-party connection. Once inside, they escalated their privileges to root level, allowing them extensive control over the system. However, rather than using this access openly, which would likely alert security teams, the attackers opted for a more covert method.

They manipulated the PAM framework to move between low-privileged accounts without needing passwords. This approach distributed their activity across lesser-monitored accounts, creating a forensic smokescreen that made detection difficult. Researchers from Group-IB identified this tactic, noting its ability to regenerate the botnet even after root access was cleaned.

Advanced Evasion Techniques

The payload used in this campaign is a modified version of the XMRig miner. It is designed to erase its binary from the disk while continuing to operate from memory, effectively evading antivirus detection. Additionally, the attackers disabled logging and altered authentication records on infected machines, further obscuring their presence.

These evasive strategies are typically seen in advanced persistent threats, where maintaining long-term access is crucial. The campaign’s reliance on trusted supply chain connections and memory-resident execution underscores its sophistication. Reviewing trends in recent ransomware analysis can provide insights into detecting similar tactics early.

Technical Details and Recommendations

The attackers exploited the pam_rootok policy within the PAM stack to impersonate users without entering passwords, facilitating the spread of malicious cronjobs. This persistence mechanism meant that merely addressing the root compromise would not eliminate the botnet.

To further evade detection, core logging services were halted, and authentication logs were tampered with, leaving minimal forensic evidence. This campaign highlights the necessity of monitoring PAM logs for unusual user activity, as rapid user transitions can indicate malicious behavior.

Security teams are advised to audit and restrict third-party access using zero trust principles, and to enhance visibility over logging services like rsyslog and auditd. Memory forensics is crucial for detecting implants that delete themselves, and understanding backdoors that exploit PAM can help identify potential threats.

Indicators of compromise include specific file artifacts and hashes related to the customized XMRig implant. Organizations should monitor these indicators to enhance their threat detection capabilities.

Strengthening defenses against such sophisticated attacks requires a combination of proactive monitoring, robust logging, and comprehensive forensic analysis.

Cyber Security News Tags:Botnet, Cryptomining, Cybersecurity, forensic analysis, Linux security, Malware, network security, PAM, threat detection, XMRig

Post navigation

Previous Post: Critical Flaw in Ruflo AI Exposes Systems to Attack
Next Post: State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks

Related Posts

XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer Cyber Security News
Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks Cyber Security News
Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks Cyber Security News
Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster Critical Chaos Mesh Vulnerabilities Let Attackers Takeover Kubernetes Cluster Cyber Security News
Chinese Cyber Espionage Targets Singapore Telecom Industry Chinese Cyber Espionage Targets Singapore Telecom Industry Cyber Security News
New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark