A covert Monero mining campaign identified as part of the V25 (Generation 26) botnet exploits trusted third-party relationships to infiltrate Linux environments. The attackers utilize a modified XMRig botnet that executes filelessly by deleting itself after launch, operating entirely in memory to avoid detection. They employ Linux PAM abuse for privilege escalation and logging suppression, effectively covering their tracks while deploying malicious cronjobs across compromised accounts.
Defense measures include memory forensics to detect the threat, monitoring PAM and audit logs, and implementing zero-trust controls for third-party connections. Group-IB analyzed this attack and emphasizes the critical supply chain risks associated with such exploits.