Group-IB reported that attackers can abuse Linux Pluggable Authentication Modules (PAM) by modifying SSH authentication settings to invoke the pam_exec module, turning a legitimate feature into a stealthy credential-theft and persistence mechanism. In the demonstrated technique, a malicious script is triggered during SSH login attempts—including failed authentications—to collect usernames and environment data and send them to a remote host, while standard logs may show only unsuccessful SSH access and not the hidden execution path.
The technique affects a core authentication framework used by services such as sshd, login, su, and passwd, making PAM configuration integrity a high-value defensive priority on Linux systems. Group-IB said the same approach could support backdoors, covert command execution, and long-term persistence, and recommended hardening measures including timely patching, enforcing SELinux or AppArmor, monitoring with Auditd and Wazuh, and using tools such as PSAD, AIDE, and rkhunter to detect unauthorized changes and suspicious activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Group-IB published a technical analysis showing how Linux PAM configuration can be modified to invoke pam_exec during SSH authentication, enabling malicious scripts to run even on failed login attempts. The write-up describes exfiltration of user and environment data via netcat while standard logs may only show failed SSH authentication, and includes hardening recommendations.
Palo Alto Networks Unit 42 published research on malware using Linux PAM authentication modules for malicious activity. The report documented PAM abuse as a persistence and credential-theft mechanism on Linux systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.