Edward Kiledjian's Threat Intel

New Linux backdoor Plague bypasses auth via malicious PAM module

A new Linux backdoor, Plague, disguised as a malicious PAM module, bypasses authentication and grants persistent SSH access. It uses advanced obfuscation, anti-debugging features, and sanitizes session traces to evade detection. The attribution of the Plague backdoor is still unknown.