Plague is a Linux backdoor implemented as a malicious Pluggable Authentication Module (PAM), primarily targeting SSH authentication workflows. By integrating into the PAM stack used by sshd, it allows an attacker with elevated installation privileges to bypass normal authentication checks and obtain covert, persistent SSH access to compromised Linux systems. Because PAM modules execute inside privileged authentication processes, Plague can influence authentication decisions directly and survive application-level updates that do not remove the malicious module.
The malware is notable for abusing a high-trust component of the Linux authentication architecture rather than relying on a conventional user-space implant. This design gives it strong persistence and makes detection more difficult if defenders focus only on traditional endpoint malware signatures. Reporting indicates it evaded traditional antivirus detection for an extended period. Detection engineering updates have also associated Plague variants with credential-theft-related logic, reinforcing its role as an authentication-layer intrusion tool.
Plague’s initial infection vector is not established, but deployment as a PAM module requires elevated privileges on the target host, making it consistent with post-compromise use after an attacker has already obtained administrative access. It has been discussed as an early example of PAM-stack-focused Linux backdooring and is referenced as the predecessor to later operator-grade PAM backdoors such as PamDOORa. Targeting is centered on Linux systems that expose or rely on SSH for remote administration, making servers and other Unix-like infrastructure the most relevant victim class.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier PAM-stack backdoor referenced for comparison with PamDOORa; Flare.io assesses PamDOORa as distinct from Plague.
Previously known Linux backdoor targeting the PAM stack.
A Linux backdoor targeting the PAM stack; no further operational details are provided in the content.
Linux PAM-based backdoor enabling silent authentication bypass and persistent SSH access; reportedly evaded detection for ~1 year (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.