New malware avoids antivirus detection, unleashes a “plague” on your devices
- Nextron Systems found a malicious Pluggable Authentication Module
- They named it Plague after finding pop culture references
- The malware is capable of wreaking havoc across high-value targets
Security researchers have found a piece of highly capable Linux malware which somehow flew the radar for a year.
Nextron Systems reported finding Plague, a malicious Pluggable Authentication Module (PAM) that grants attackers persistent, covert access to compromised systems.
“The Plague backdoor represents a sophisticated and evolving threat to Linux infrastructure, exploiting core authentication mechanisms to maintain stealth and persistence,” the researchers explained. “Its use of advanced obfuscation, static credentials, and environment tampering makes it particularly difficult to detect using conventional methods.”
Manual inspection
The malware was named Plague after finding a reference to Mr. Plague, a character from the 1995 movie Hackers, in its code.
The researchers said that multiple samples were uploaded to VirusTotal over the past year, yet none were flagged as malicious, which could indicate the backdoor managed to evade public scrutiny and antivirus detection.
Plague integrates deeply into the authentication stack, survives system updates, and leaves minimal forensic traces, the experts explained.
It employs evolving string obfuscation techniques, including XOR, KSA/PRGA-like routines, and DRBG layer. It also features anti-debugging checks and session stealth mechanisms that erase all traces of activity. Compiler metadata also showed that it is in active development.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
For cybercriminals, there are multiple benefits to malware hiding inside PAM systems.
According to a CyberInsider report, Plague can steal login credentials, making it particularly dangerous on high-value Linux systems such as bastion hosts, jump servers, and cloud infrastructure.
“A compromised bastion host or jump server can provide attackers with a foothold to move laterally across internal systems, escalate privileges, or exfiltrate sensitive data,” the publication argues.
Furthermore, a compromised cloud environment could grant the attackers access to multiple virtual machines or services all at once.
Since Plague is still not being flagged by the best antivirus tools, Nextron advises admins to manually inspect their devices, including auditing the /lib/security directory for shady PAM modules, monitoring PAM configuration files in /etc/pam.d/ for changes, and looking for suspicious logins in authentication logs.
Via The Register
You might also like
Nextron Systems found a malicious Pluggable Authentication Module They named it Plague after finding pop culture references The malware is capable of wreaking havoc across high-value targets Security researchers have found a piece of highly capable Linux malware which somehow flew the radar for a year. Nextron Systems reported finding…
Recent Posts
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023