Linux PAM Backdoors Show 0 Antivirus Detections on VirusTotal

cyb3rops · x · 2026-07-30

Security researchers point out that Linux PAM (Pluggable Authentication Modules) remains one of the highest-value persistence points on the system, yet it is surprisingly under-monitored.

A recent analysis of malicious PAM backdoors and credential stealers revealed that every malicious sample had 0 detections on VirusTotal at the time of analysis. PAM is an ideal hiding spot because a single malicious module can transparently intercept credentials, bypass authentication, establish persistence, enable account takeover, and communicate with C2 infrastructure, all while the rest of the authentication stack continues to function normally.

Original post →

More from Safety

Safety channel →