CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6321

As cited

Copy frozen at (site build).

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

A cryptomining campaign uses Linux Pluggable Authentication Modules (PAM) to execute malicious code under low-privileged user accounts rather than root, a technique designed to evade security operations center (SOC) detection. The attackers abandon elevated privileges to blend in with normal user activity and reduce the visibility of their operations.

Why it matters: SOC analysts and Linux administrators need to monitor PAM configurations and low-privilege process execution patterns, as this technique defeats common detection rules that focus on root-level activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary