Skidmap is a Linux cryptomining malware family incorporating rootkit functionality to conceal activity and maintain unauthorized access. It uses a malicious Pluggable Authentication Module (PAM) to establish a hidden authentication backdoor that can grant root access when a hardcoded secret is supplied, bypassing normal password verification. Skidmap has also been associated with credential capture through PAM abuse. Its rootkit capabilities include Linux kernel-module functionality, while its persistence and resilience mechanisms include monitoring critical processes. Skidmap weakens host protections by checking and changing SELinux enforcement to permissive mode and by replacing legitimate system utilities with malicious lookalikes. It can retrieve, unpack, and decrypt compressed archives to stage additional components. The malware targets Linux systems and is used to consume victim compute resources for unauthorized cryptocurrency mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“LKM rootkits leverage different kernel features to hook kernel functions” and are used “to hide malicious activity by hooking execution flow.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux cryptominer rootkit that used a malicious PAM module to maintain a hidden backdoor password, allowing root access with a hardcoded secret regardless of the real password.
Referenced as a Linux malware family known to leverage PAM APIs for credential logging and remote access.
Linux malware/rootkit referenced as leveraging PAM abuse for persistence, credential capture, and maintaining unauthorized access.
Malware mentioned as an example of abusing Linux PAM for persistence, credential capture, and unauthorized access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.