PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague / pam_exec Technique Lineage — Threadlinqs Intelligence
As of 2026-07-30, PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague / pam_exec Technique Lineage is a high-severity malware threat attributed to darkworm, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1772 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: darkworm · FINANCIAL
PamDOORa is a commercialized Linux backdoor sold since at least April 2026 on the Rehub cybercrime forum by the actor 'darkworm' that abuses the Pluggable Authentication Module (PAM) framework — via
Provenance note: this threat ID's original HUNT seed (an 'XMRig Covert Ops'/pam_rootok-abuse claim attributed to Group-IB) was independently re-verified during RESEARCH and confirmed unverifiable/fabricated (no corroborating source anywhere, an invalid 66-character 'SHA-256' hash, and a suspicious same-day 'publish date'). Rather than fabricate data to force that fake narrative through, RESEARCH substituted Group-IB's actual, multi-outlet-corroborated 2026 PAM-abuse coverage — the real threat the fake content appears to have been garbled from — and documented it here in full, using only independently verified facts.
PamDOORa is a Linux post-exploitation backdoor first publicly reported on 7-8 May 2026 by Flare researcher Assaf Morag and Group-IB's DFIR team after it surfaced as a commercial listing (initially priced at $1,600, discounted to $900 by 9 April 2026) on the Russian-language cybercrime forum Rehub, offered by the actor 'darkworm'. The tool weaponizes the Linux Pluggable Authentication Module (PAM) stack — specifically the pam_exec module, which is designed to run external commands during authentication events — by injecting malicious directives into PAM configuration files such as /etc/pam.d/sshd. During SSH login attempts, the injected script harvests PAM environment variables (PAM_USER, PAM_RHOST, PAM_SERVICE) plus usernames, timestamps, and other session data, and exfiltrates them in plaintext to an attacker-controlled server, typically via netcat. Because the malicious pam_exec entry is set with the 'optional' control flag, execution neither breaks the login flow nor raises suspicion, and because operators deliberately trigger the script on failed authentication attempts, standard authentication logs record only a routine failed login — leaving no visible trace of the underlying credential exfiltration in application-level logs.
PamDOORa is not a novel technique in isolation: it is the latest commercialized iteration of a PAM-abuse lineage that Group-IB DFIR researchers Vito Alfano and Nam Le Phuong first documented on 6 September 2024 in 'The Duality of the Pluggable Authentication Module,' describing the same pam_exec-based approach (using a script named tn.sh to exfiltrate PAM_RHOST/PAM_SERVICE/PAM_USER data to a demonstration listener at 10.0.0.142:1234) as a technique 'not yet included in the MITRE ATT&CK framework' at that time. In the interim, Nextron Systems (Pierre-Henri Pezier) publicly disclosed a closely related, more sophisticated backdoor dubbed 'Plague' on 1 August 2025: a malicious PAM module masquerading as libselinux.so.8 (and later libse.so) that bypasses SSH authentication entirely via hardcoded 'magic' passwords, uses layered XOR/RC4-style/DRBG string obfuscation, performs anti-debug and anti-sandbox checks, and scrubs SSH_CONNECTION/SSH_CLIENT environment variables and shell history (HISTFILE redirected to /dev/null) to erase forensic evidence. Plague samples had circulated on VirusTotal undetected by all antivirus engines since July 2024, with active development continuing through at least March 2025.
The broader PAM-backdoor technique family also has a well-established track record in financially motivated operations: Group-IB's 8 May 2025 report 'Understanding Credential Harvesting via PAM' documents how UNC1945 and, more extensively, UNC2891 (both tracked by Mandiant) modify pam_unix.so to log plaintext credentials to hidden files as part of long-running, multi-year intrusions into Solaris and Linux estates. UNC2891 combined its SLAPSTICK PAM backdoor (hardcoded per-server 'magic password' enabling passwordless SSH access) with the CAKETAP Solaris/Linux kernel rootkit, which manipulates ATM switch authorization messages (ARQC/ARPC) to approve fraudulent card transactions, and a custom variant of the public TINYSHELL backdoor — together forming the toolset behind an attempted multi-bank ATM cash-out operation. PamDOORa's emergence as an off-the-shelf, purchasable product signals that
Weaknesses (CWE)
CWE-798, CWE-288, CWE-306
Target sectors: financial services, managed service providers, government administration, technology, critical infrastructure
Target regions: Global
Detections & IOCs
As of 2026-08-09, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1556, T1556, T1556, T1140, T1027, T1070, T1685, T1036, T1574, T1574