As cited
Copy frozen at (site build).
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
A cryptomining campaign uses Linux Pluggable Authentication Modules (PAM) to execute malicious code under low-privileged user accounts rather than root, a technique designed to evade security operations center (SOC) detection. The attackers abandon elevated privileges to blend in with normal user activity and reduce the visibility of their operations.
Why it matters: SOC analysts and Linux administrators need to monitor PAM configurations and low-privilege process execution patterns, as this technique defeats common detection rules that focus on root-level activity.
- Source published
- First seen by Cybersecurity Tracker