Abuses – Bitcoin Platform https://bitcoinplatform.com Breaking Crypto News and Blockchain updates Sun, 20 Sep 2026 11:37:07 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1.1 https://bitcoinplatform.com/wp-content/uploads/2026/09/cropped-fevi-18-32x32.png Abuses – Bitcoin Platform https://bitcoinplatform.com 32 32 Cryptominer Abuses Linux PAM to Hide From SOC Analysts https://bitcoinplatform.com/cryptominer-abuses-linux-pam-to-hide-from-soc-analysts/ https://bitcoinplatform.com/cryptominer-abuses-linux-pam-to-hide-from-soc-analysts/#respond Sun, 20 Sep 2026 11:37:07 +0000 https://bitcoinplatform.com/cryptominer-abuses-linux-pam-to-hide-from-soc-analysts/ A recent investigation has revealed a shift in tactics by a cryptomining operation targeting Linux servers. Instead of maintaining root access, the operators have opted to impersonate low-privileged users to evade detection by security operations centers (SOCs).

This discovery was made by Group-IB in May 2026 during a Monero mining campaign that infiltrated a network through a trusted third-party relationship. The attackers escalated their privileges to root level, leveraging the pam_rootok policy in Linux Pluggable Authentication Modules (PAM) to assume the identities of standard accounts without requiring their passwords.

By impersonating low-privileged users, the cryptomining operators created a “forensic smokescreen” to hide their activities. They spread their actions across multiple accounts that were not actively monitored, making it difficult for responders to detect and remove the malicious implant. Additionally, they disabled core logging services and manipulated authentication logs to minimize traces of their actions.

To further conceal their activities, the operators implemented process masquerading and used a Java/Agent user agent for mining traffic to blend in with legitimate web application traffic. The malware employed was a modified version of XMRig 6.25.0, compiled with musl libc and designed to delete its own binary from disk upon startup, running entirely in memory to avoid detection by conventional disk scans.

The malware utilized XOR keys to encrypt its configuration, with Group-IB identifying a hardcoded campaign identifier linked to a broader family of campaigns aimed at aggregating hash rates from compromised hosts. In response to these findings, Group-IB recommended organizations to send logs to an external tamper-proof system in real-time, restrict connections from vendors and clients, and conduct memory forensics due to the self-deleting behavior of the malware.

This shift in tactics by cryptomining operators demonstrates a continued evolution in cyber threats and the need for organizations to remain vigilant in detecting and responding to such attacks. By staying informed and implementing best practices in cybersecurity, businesses can better protect themselves against these increasingly sophisticated threats.

]]>
https://bitcoinplatform.com/cryptominer-abuses-linux-pam-to-hide-from-soc-analysts/feed/ 0