Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet

Posted on July 30, 2026 By CWS

A recent cryptomining campaign targeting Linux systems employs a sophisticated technique to remain undetected within compromised networks. By leveraging the Pluggable Authentication Modules (PAM) framework, attackers are able to discreetly mine Monero cryptocurrency without triggering standard security alerts.

Exploiting PAM for Stealth

The cyberattack was initiated in May 2026, when threat actors infiltrated a network via a trusted third-party connection. Once inside, they escalated their privileges to root level, allowing them extensive control over the system. However, rather than using this access openly, which would likely alert security teams, the attackers opted for a more covert method.

They manipulated the PAM framework to move between low-privileged accounts without needing passwords. This approach distributed their activity across lesser-monitored accounts, creating a forensic smokescreen that made detection difficult. Researchers from Group-IB identified this tactic, noting its ability to regenerate the botnet even after root access was cleaned.

Advanced Evasion Techniques

The payload used in this campaign is a modified version of the XMRig miner. It is designed to erase its binary from the disk while continuing to operate from memory, effectively evading antivirus detection. Additionally, the attackers disabled logging and altered authentication records on infected machines, further obscuring their presence.

These evasive strategies are typically seen in advanced persistent threats, where maintaining long-term access is crucial. The campaign’s reliance on trusted supply chain connections and memory-resident execution underscores its sophistication. Reviewing trends in recent ransomware analysis can provide insights into detecting similar tactics early.

Technical Details and Recommendations

The attackers exploited the pam_rootok policy within the PAM stack to impersonate users without entering passwords, facilitating the spread of malicious cronjobs. This persistence mechanism meant that merely addressing the root compromise would not eliminate the botnet.

To further evade detection, core logging services were halted, and authentication logs were tampered with, leaving minimal forensic evidence. This campaign highlights the necessity of monitoring PAM logs for unusual user activity, as rapid user transitions can indicate malicious behavior.

Security teams are advised to audit and restrict third-party access using zero trust principles, and to enhance visibility over logging services like rsyslog and auditd. Memory forensics is crucial for detecting implants that delete themselves, and understanding backdoors that exploit PAM can help identify potential threats.

Indicators of compromise include specific file artifacts and hashes related to the customized XMRig implant. Organizations should monitor these indicators to enhance their threat detection capabilities.

Strengthening defenses against such sophisticated attacks requires a combination of proactive monitoring, robust logging, and comprehensive forensic analysis.

Cyber Security News Tags:Botnet, Cryptomining, Cybersecurity, forensic analysis, Linux security, Malware, network security, PAM, threat detection, XMRig

Post navigation

Previous Post: Critical Flaw in Ruflo AI Exposes Systems to Attack
Next Post: State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks

Related Posts

Android 17 Enhances Security with Advanced Protection Android 17 Enhances Security with Advanced Protection Cyber Security News
OverlayPhantom Trojan Exploits Android Devices OverlayPhantom Trojan Exploits Android Devices Cyber Security News
Bots Dominate Global Web Traffic, Surpassing Humans Bots Dominate Global Web Traffic, Surpassing Humans Cyber Security News
FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof FBI Warns of Hackers Altering Photos Found on Social Media to Use as Fake Proof Cyber Security News
Mirai Botnets Escalate Global Cyber Threats Mirai Botnets Escalate Global Cyber Threats Cyber Security News
New ShadowCaptcha Attack Exploiting Hundreds of WordPress Sites to Tricks Victims into Executing Malicious Commands New ShadowCaptcha Attack Exploiting Hundreds of WordPress Sites to Tricks Victims into Executing Malicious Commands Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats
  • State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks
  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats
  • State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks
  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark