'Plague' Malware Exploits Pluggable Authentication Module To Breach Linux Systems
CyberArk, Thursday, August 7th, 2025
Understanding the 'Plague' Pluggable Authentication Module (PAM) backdoor in Linux systems
'Plague' represents a newly identified Linux backdoor that has quietly evaded detection by traditional antivirus solutions for over a year. Its primary mechanism involves operating as a malicious PAM, allowing attackers to silently bypass system authentication and establish persistent SSH access to compromised Linux systems.