Skidmap is a Linux-targeting cryptomining malware family associated with rootkit functionality and covert backdoor access. It is designed to compromise Linux systems, weaken host security controls, maintain resilient persistence, and abuse victim compute resources for unauthorized cryptocurrency mining. The malware has been described as a Linux cryptominer rootkit and is notable for combining monetization with stealth and privileged access mechanisms.
Skidmap can reduce host defenses by checking for SELinux controls and setting SELinux to permissive mode, thereby weakening mandatory access protections. It also uses masquerading and binary replacement techniques, including replacing legitimate system utilities with trojanized versions, to support persistence and defense evasion. The malware monitors critical processes to preserve operational resiliency on infected hosts.
A distinctive feature attributed to Skidmap is abuse of Pluggable Authentication Modules (PAM). It has used a malicious PAM module to maintain a hidden backdoor password that grants root access regardless of the legitimate password, providing persistent privileged access and post-compromise control. Skidmap has also been cited alongside other Unix-focused threats as an example of malware exploiting PAM APIs for credential logging and remote access, though the strongest support is for PAM-based backdoor access rather than broad credential theft behavior.
Skidmap is also reported to download, unpack, and decrypt compressed payload archives, indicating staged payload handling and support for follow-on components. It is part of a broader class of Linux cryptojacking threats that target enterprise and organizational infrastructure because of available compute capacity and reliability. In addition to mining-related objectives, its rootkit and backdoor capabilities make it relevant as a persistence and unauthorized-access threat beyond simple resource hijacking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The key insight for an attacker: /etc/pam.d/ is not protected by SIP. It can be modified with root... Adding one line to /etc/pam.d/sudo with optional control is all it takes.
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
PAM provides the essential capability to centralize how secure authentication happens, its flexibility can be abused by attackers to establish persistence through malicious PAM modules. By introducing custom modules or modifying existing configurations, attackers can manipulate authentication flows to capture credentials, manipulate logging to evade detection, grant unauthorized access, or execute malicious code.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux cryptominer rootkit that used a malicious PAM module to maintain a hidden backdoor password, allowing root access with a hardcoded secret regardless of the real password.
Referenced as a Linux malware family known to leverage PAM APIs for credential logging and remote access.
Linux malware/rootkit referenced as leveraging PAM abuse for persistence, credential capture, and maintaining unauthorized access.
A Linux malware that uses rootkit capabilities to hide cryptocurrency mining payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.