Linux PAM Backdoors Show 0 Antivirus Detections on VirusTotal
cyb3rops · x · 2026-07-30
Security researchers point out that Linux PAM (Pluggable Authentication Modules) remains one of the highest-value persistence points on the system, yet it is surprisingly under-monitored.
A recent analysis of malicious PAM backdoors and credential stealers revealed that every malicious sample had 0 detections on VirusTotal at the time of analysis. PAM is an ideal hiding spot because a single malicious module can transparently intercept credentials, bypass authentication, establish persistence, enable account takeover, and communicate with C2 infrastructure, all while the rest of the authentication stack continues to function normally.
More from Safety
- AI Model Improves Attack on 7-Round AES, Sponsored by Anthropic with $100k Compute — jedisct1 · 2026-07-30
- AI Age Verification Dilemma: Protect Children or Enable Surveillance? — ShakeelHashim · 2026-07-30
- Why Enterprises Block Direct Access to PyPI, NPM, and Maven — _jaydeepkarale · 2026-07-30
- New Approach to AI Alignment: Low-Dimensional Structure in Trillion-Parameter Models — geoffreyirving · 2026-07-30
- Anthropic's Safety Pitch Criticized as a Tactic Against Open-Source Rivals — SerialRealer · 2026-07-30
- Walmart Faces Privacy Lawsuit Over Facial Recognition Database — Yamapama · 2026-07-30