Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
cybersecurity researchers have uncovered a new Linux backdoor named PamDOORa, being sold for $1,600 on the Rehub Russian cybercrime forum by a threat actor known as "darkworm." This sophisticated tool leverages the Pluggable Authentication Module (PAM) framework to provide persistent SSH access and harvest credentials.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers note that PamDOORa represents an evolution in operator-grade tooling due to its integrated features and builder pipeline.
Covert access is unlocked by a magic password plus a specific TCP port combination.
Abuses pam_exec to run attacker scripts during the authentication event.
Once installed, the backdoor injects a malicious PAM module that produces a file called pam_linux.so, loaded into the authentication stack alongside legitimate system modules. This design allows it to blend in with normal system files rather than replacing them.
The malicious module is named to blend in with legitimate PAM modules (e.g. pam_linux.so).
The backdoor is built to manipulate authentication log files including lastlog, btmp, utmp, and wtmp, wiping away any trace that an attacker connected to the server.
Tampers with authentication logs to erase traces of malicious logins.
PAM's modularity allows malicious modifications, which PamDOORa exploits to steal credentials from legitimate users and tamper with authentication logs to erase traces of its activity.
Researchers note that PamDOORa represents an evolution in operator-grade tooling due to its integrated features and builder pipeline.
Covert access is unlocked by a magic password plus a specific TCP port combination.
The latest findings from Flare.io show that PamDOORa, besides enabling credential theft, incorporates anti-forensic capabilities to methodically tamper with authentication logs to erase traces of malicious activity.
Credentials submitted by legitimate users during login are intercepted within the PAM stack, encrypted using XOR with a runtime-generated key, and written to /tmp with randomly generated filenames and timestamps.
PAM's modularity allows malicious modifications, which PamDOORa exploits to steal credentials from legitimate users and tamper with authentication logs to erase traces of its activity.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux PAM-based post-exploitation backdoor that requires root to install, plants a malicious PAM module, captures plaintext SSH passwords and optional SSH key passphrases, provides covert persistent SSH access via a magic password and specific TCP port, stores harvested credentials locally, and includes anti-forensic and anti-debugging features.
Linux PAM-based backdoor that provides persistent SSH access, harvests credentials, operates with root privileges, uses a magic password and specific TCP port combination for access, and can tamper with authentication logs to hide activity.
Linux backdoor that abuses the PAM authentication framework to intercept SSH credentials, provide persistent covert SSH access, and erase attacker traces from authentication logs. It is described as a post-exploitation tool requiring root access before deployment.
A Linux PAM-based backdoor that enables persistent SSH access using a magic password and specific TCP port combination, harvests credentials from legitimate users authenticating to the compromised system, and includes anti-forensic log tampering capabilities to erase traces of activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.