Back to IntelRead Original Source
Intel Node
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials
lowapt2026-05-08T08:41:00+00:00source excerpt
aptmalwarelinux
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called "darkworm." The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP port combination.