securityonline.info 8/5/2026, 7:51:33 AM · external

XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts

XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
Developing story campaign 2 articles tracked
XMRig botnet exploits Linux PAM to hide fileless Monero miner
CyberSIXT Evidence Panel
Primary Source group-ib.com

A covert Monero mining campaign identified as part of the V25 (Generation 26) botnet exploits trusted third-party relationships to infiltrate Linux environments. The attackers utilize a modified XMRig botnet that executes filelessly by deleting itself after launch, operating entirely in memory to avoid detection. They employ Linux PAM abuse for privilege escalation and logging suppression, effectively covering their tracks while deploying malicious cronjobs across compromised accounts.

Defense measures include memory forensics to detect the threat, monitoring PAM and audit logs, and implementing zero-trust controls for third-party connections. Group-IB analyzed this attack and emphasizes the critical supply chain risks associated with such exploits.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline