Researchers have disclosed PamDOORa, a Linux backdoor that abuses the Pluggable Authentication Module (PAM) framework to steal SSH credentials and maintain covert persistence on already-compromised x86_64 systems. Advertised on the Russian-speaking cybercrime forum Rehub by an actor using the alias "darkworm," the malware is positioned as a post-exploitation toolkit and was reportedly offered for sale with its source code. It intercepts credentials from legitimate users during authentication by abusing pam_exec and inserting a malicious PAM component into the login stack.
PamDOORa also enables hidden SSH access through a magic password tied to a specific TCP port, while anti-forensic functions tamper with records such as lastlog, btmp, utmp, and wtmp to conceal activity and complicate investigations. Researchers said the malware appears to require prior root-level compromise for deployment, and there is no confirmed evidence yet of active in-the-wild attacks, but they described it as a more mature, operator-grade evolution of earlier PAM backdoor concepts because of its modular design, anti-debugging features, network-aware triggers, and builder pipeline.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported a new Linux PAM-based backdoor named PamDOORa that steals SSH credentials, enables covert SSH access via a magic password and specific TCP port, and tampers with authentication logs such as lastlog, btmp, utmp, and wtmp. Group-IB and Flare.io described it as requiring prior root compromise for deployment and noted there was no evidence of real-world attacks at the time of disclosure.
A threat actor using the alias "darkworm" advertised the PamDOORa malware on the Russian-speaking cybercrime forum Rehub as a post-exploitation toolkit for x86_64 Linux systems. Reporting indicates the source code was offered for sale, with one account noting the price later dropped from $1,600 to $900.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.