Plague is a Linux backdoor that operates by installing a malicious Pluggable Authentication Module (PAM), reportedly targeting the SSH authentication stack. By embedding itself in PAM, it can bypass normal authentication checks and provide covert persistent SSH access on compromised systems. Because PAM modules execute within privileged authentication processes, Plague gains a highly sensitive position in the login flow and can survive ordinary application updates.
The malware is associated with Linux environments and requires elevated privileges for installation, indicating it is most likely used after an attacker has already obtained administrative access through another intrusion path. Public reporting describes its initial infection vector as unknown. Detection engineering references also indicate variants tied to credential theft, consistent with the broader risks of PAM abuse in which authentication material can be exposed during processing.
Plague is notable as one of the earlier known Linux backdoors focused specifically on the PAM stack and has been cited as a predecessor to later PAM-based implants such as PamDOORa. It has been characterized as capable of evading traditional antivirus detection for an extended period. The malware illustrates how adversaries can abuse Linux authentication infrastructure to achieve stealthy persistence and unauthorized remote access on servers, especially systems exposing SSH services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier PAM-stack backdoor referenced for comparison with PamDOORa; Flare.io assesses PamDOORa as distinct from Plague.
Previously known Linux backdoor targeting the PAM stack.
A Linux backdoor targeting the PAM stack; no further operational details are provided in the content.
Linux PAM-based backdoor enabling silent authentication bypass and persistent SSH access; reportedly evaded detection for ~1 year (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.