A recent report from Group-IB reveals that a cryptomining operation has exploited Linux PAM to evade detection by security operations centers. The attackers abandoned root access to masquerade as low-privileged users, effectively creating a 'forensic smokescreen'. This was achieved by abusing the pam_rootok policy, which allowed them to impersonate standard user accounts without passwords.
They hindered log monitoring and tampered with authentication logs to cover their tracks, while also employing process masquerading to disguise their mining activities. The mining implant is a modified XMRig version that deletes its binary from disk, operating solely in memory to avoid detection. Group-IB suggests organizations enhance their security by forwarding logs in real-time to tamper-proof external systems and searching for transient artifacts.