Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Posted on May 8, 2026 By CWS

Security experts have unearthed a new Linux backdoor, dubbed PamDOORa, which is being marketed on the Rehub Russian cybercrime forum by an individual known as “darkworm.” Initially priced at $1,600, the backdoor’s cost was later reduced to $900. Designed as a Pluggable Authentication Module (PAM)-based tool, PamDOORa ensures persistent SSH access by utilizing a specific password and TCP port combination. It also poses a threat by capturing credentials from any authenticated users on compromised systems.

PamDOORa’s Functionality and Risks

PamDOORa operates as a post-exploitation toolkit within the PAM framework, a critical security component in Unix/Linux systems. This framework allows system administrators to integrate diverse authentication methods. However, when maliciously modified, PAM modules can introduce backdoors and facilitate credential theft. According to Assaf Morag from Flare.io, PamDOORa persists on x86_64 Linux systems, making it a significant threat.

The backdoor is notable for its ability to harvest credentials and tamper with authentication logs, effectively hiding traces of illicit activities. This makes it a sophisticated tool compared to other PAM-based backdoors, which often lack such advanced capabilities.

Exploiting PAM’s Vulnerabilities

Although PAM offers robust security features, its modular nature can be exploited. Group-IB has previously highlighted the risks associated with PAM, particularly when modules operate with root privileges. Malicious modifications can grant unauthorized access or control over systems, especially via modules like pam_exec, which can execute external commands.

The PamDOORa backdoor takes advantage of these vulnerabilities by manipulating PAM configurations to execute scripts, thereby securing a persistent and stealthy presence on target systems.

Potential Threats and Market Response

Despite its capabilities, there is currently no evidence of PamDOORa being deployed in actual cyber attacks. However, the potential threat it poses cannot be overlooked. Infection chains involving PamDOORa may require initial root access, after which the PAM module can be deployed to capture credentials and establish ongoing SSH access.

The decision by “darkworm” to reduce the asking price of PamDOORa suggests either a lack of demand or a strategic move to increase sales velocity. This backdoor’s integration of debug-resistant features and network-aware triggers positions it as a formidable tool for cybercriminals seeking more than just basic exploits.

In conclusion, PamDOORa exemplifies the ongoing evolution of cyber threats targeting Linux systems. As cybersecurity landscapes continue to shift, staying informed about such developments is crucial for maintaining robust defenses and ensuring system security.

The Hacker News Tags:Backdoor, credential harvesting, cyber threat, Cybercrime, Cybersecurity, darkworm, Flare.io, Group-IB, Linux PAM, Linux security, Malware, PAM modules, PamDOORa, SSH credential theft

Post navigation

Previous Post: DarkMoon Launches AI-Driven Penetration Testing Platform
Next Post: Cyberattack Disrupts Canvas Platform as Finals Near

Related Posts

Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues The Hacker News
ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files The Hacker News
Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign Water Curse Employs 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign The Hacker News
Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030
  • Enhancing SOC Efficiency by Reducing IOC Noise
  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030
  • Enhancing SOC Efficiency by Reducing IOC Noise
  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark