Close Menu
TechurzTechurz
    What's Hot

    Snap alums unveil Ghost Angels fund

    May 30, 2026

    As the browser wars heat up, here are the hottest alternatives to Chrome and Safari in 2026

    May 30, 2026

    After Nvidia’s $20B not-acqui-hire, AI chip startup Groq reportedly raising $650M

    May 29, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Snap alums unveil Ghost Angels fund
    • As the browser wars heat up, here are the hottest alternatives to Chrome and Safari in 2026
    • After Nvidia’s $20B not-acqui-hire, AI chip startup Groq reportedly raising $650M
    • After Nvidia’s $20B not-aqui-hire, AI chip startup Groq reportedly raising $650M
    • Cognition’s Scott Wu says AI coding agents shouldn’t replace humans
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - How ‘Plague’ infiltrated Linux systems without leaving a trace
    Security

    How ‘Plague’ infiltrated Linux systems without leaving a trace

    TechurzBy TechurzAugust 4, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    malware skull
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Security researchers have discovered an unusually evasive Linux backdoor, undetected even by VirusTotal, compromising systems as a malicious pluggable authentication module (PAM). Dubbed “Plague” by Nextron researchers, the stealthy backdoor lets attackers slip past authentication unnoticed and establish persistent secure shell (SSH) access.

    “Plague integrates deeply into the authentication stack, survives system updates, and leaves almost no forensic traces,” the researchers said in a blog post. “Combined with layered obfuscation and environment tampering, this makes it exceptionally hard to detect using traditional tools.”

    Disguising itself as PAM, Linux’s trusted authentication framework, the implant allows attackers covert access. Active since July 29, 2024, it has evolved with new variants appearing as recently as March 2025, researchers added.

    The payloads observed by Nextron bore compilation traces for Debian, Ubuntu, and other distributors, suggesting broader targeting across Linux environments.

    Integrating into the authentication stack

    Plague’s architecture allows it to deeply integrate into the system’s authentication stack, operating through a benign-looking shared library file (libselinus.so.8) while hijacking PAM functions like “pam_sm_authenticate(),” the very mechanism that verifies user credentials on login.

    The injection makes Plague part of the login process, granting attackers a hidden backdoor via a hardcoded password without user authentication, researchers added. Because it’s operating at the authentication level, no separate malware loader or persistence mechanism is needed. Backdoor is triggered any time the PAM stack is invoked, such as through SSH or sudo.

    The design of hijacking legitimate system behavior also makes Plague resistant to upgrades and difficult to detect with traditional security tools, including antivirus engines on VirusTotal.

    “Although several variants of this backdoor have been updated to VirusTotal over the past year, not a single antivirus engine flags them as malicious,” the researchers said. “ To our knowledge, there are no public reports or detection rules available for this threat, suggesting that it has quietly evaded detection across multiple environments.”

    According to screenshots shared in the blog, dozens of variants uploaded to VirusTotal over the past year registered 0/66 detections.

    From obfuscation to audit evasion

    Plague’s stealth begins at compile time. Early versions used simple XOR-based string encoding, but later variants deployed multi-layer encryption, including custom KSA/PRGA routines and DRBG-based stages, to obfuscate decrypted payloads and strings.

    The use of advanced cryptographic routines, including algorithms like the Key Scheduling algorithm (KSA), the Pseudo-Random Generation algorithm (PRGA), and Deterministic Random Bit Generation (DRBG), guarantees a layered protection for evading both static signature scanning and sandbox-based analysis tools.
    Despite its long runtime, the attribution of Plague remains unknown. Authors of the malware, however, did drop some clues after the de-obfuscation routines. A sample named “hijack” made a reference to the movie “Hackers” in a message printed after “pam-authenticate.” “Uh. Mr. The Plague, sir? I think we have a hacker,” the message said.
    Nextron recommends adopting behavioral, memory-based, and PAM-focused forensic strategies. Additionally, security teams are advised to actively audit PAM configurations, monitor newly dropped .so files in /lib/security/, and track environment-level tampering or suspicious cleanup behaviors.

    infiltrated Leaving Linux Plague systems trace
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhy continuous security improvement for developers is the key to renewed resilience
    Next Article iPhone just tipped for killer OLED upgrade that could leapfrog Samsung phones
    Techurz
    • Website

    Related Posts

    Opinion

    Parallel Web Systems hits $2B valuation five months after its last big raise

    April 29, 2026
    Opinion

    Commonwealth Fusion Systems leans on magnets for near-term revenue

    April 2, 2026
    Opinion

    Conntour raises $7M from General Catalyst, YC to build an AI search engine for security video systems

    March 26, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,289

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202620

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202518
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.