New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Published: (May 8, 2026 at 04:41 AM EDT)
1 min read

Source: The Hacker News

New Linux PamDOORa Backdoor

Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that’s being advertised on the Rehub Russian cyber‑crime forum for $1,600 by a threat actor called “darkworm.”

The backdoor is designed as a Pluggable Authentication Module (PAM)‑based post‑exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP port combination.

0 views
Back to Blog

Related posts

Read more »