Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

July 31, 2026

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

July 31, 2026

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev

July 30, 2026
Facebook X (Twitter) Instagram
Friday, July 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Cryptominer Abuses Linux PAM to Hide From SOC Analysts
News

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

Team-CWDBy Team-CWDJuly 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A cryptomining operation has been observed abandoning root access on compromised Linux servers in favor of impersonating low-privileged users, a deliberate downgrade designed to avoid the alerts that root activity triggers in a security operations center (SOC).

According to new research from Group-IB published on July 30, the Monero mining campaign was identified in May 2026 after operators reached a victim network through a trusted third-party relationship. 

They escalated to root, then abused the pam_rootok policy in Linux Pluggable Authentication Modules (PAM) to assume the identities of multiple standard accounts without needing their passwords.

Read more on cryptojacking crews: Cryptojacking Gang TeamTNT Make a Comeback

Hiding From Analysts and Logs

Group-IB called the result “a forensic smokescreen”. By scattering activity and redundant cron job persistence across accounts nobody was monitoring, the operators ensured that a responder who cleaned up the root compromise would find the implant regenerating from the shadowed accounts.

They also stopped core logging services and tampered with authentication logs, leaving minimal on-disk trace of either the privilege escalation or the PAM manipulation that followed it.

Concealment extended to the process and network layers. A custom flag enabled process masquerading, spoofing legitimate names such as ssh in process listings, which Group-IB mapped to MITRE technique T1564.013.

Mining traffic carried a Java/Agent user agent to blend its Stratum packets into ordinary web application flows.

A Miner That Deletes Itself

The implant is a modified build of XMRig 6.25.0, cross-compiled with musl libc and carrying a hardcoded banner identifying it as a private botnet version. On startup it creates a file-based mutex at /tmp/.lock so only one instance runs, avoiding the resource contention that would destabilize the host and alert administrators.

It then deletes its own binary from disk while continuing to run, moving entirely into memory, which Group-IB noted leaves conventional disk scans clean.

Once resident, the malware reads the host’s CPU topology and spawns worker threads accordingly, interacting with kernel model-specific registers (MSR) and allocating Huge Pages to maximize hash rate. A companion bash script terminates competing miners.

Layered XOR keys concealed the configuration. Decrypting them exposed a hardcoded campaign identifier that Group-IB linked to a wider family used to aggregate hash rates across compromised hosts.

The firm urged organizations to forward logs in real time to a tamper-proof external system, restrict cross-environment connections from vendors and clients and hunt for transient artifacts such as the /tmp/.lock mutex, since the self-unlinking behavior makes memory forensics essential.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Team-CWD
  • Website

Related Posts

News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

July 31, 2026
News

NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Dev

July 30, 2026
News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

July 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Watch out for SVG files booby-trapped with malware

September 22, 2025

2025’s most common passwords were as predictable as ever

January 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.