| SHA256 | Name | Description |
|---|---|---|
01193b3f2299b6fa849824e6b3e7276d1b9d23c62dc06b9cefc31ade1bab5201 |
pam_unix.so |
Authentication bypass with hardcoded password and credential harvesting. |
a60040a22cbb9db1a20dc2814249a7088f82fcb4fbc0fb1535c37700ee11c271 |
bd.bin |
Rust-based dropper deploying a PAM backdoor with C2 support. |
99e69fe905fef0d4f0bac72ab55e6427163552c4972f1640e52ac9fccea66623 |
stooge1 |
Manual PAM symbol hijacking to steal plaintext credentials. |
ccf20313c97946ac9b20a95486811b801113d7828d66b90a149813d79d5d8aca |
pam_backdoor.so |
Logs intercepted usernames and passwords to a hidden file. |
c7022836a3f92a6589df7cce99ee3db69ce0a98a7c266ba90a8ec5e37227329e |
pam_backdoor.so |
Captures plaintext credentials and stores them for later retrieval. |
5dc45286ff0904add55a4c2b286f0e79c7b880dfa21c6badbb5f814fefd7476e |
pam_backdoor.so |
Exfiltrates stolen credentials via outbound HTTP requests. |
18e87a07ebb1995e1822e0609f221b13d3d86588b5575509fc085f0d385a905b |
pam_backdoor.so |
Stealthy credential harvesting while allowing normal authentication. |
56d44489e8a4d17f59608730e90c2b24149c9cd9a6dd6bad1c709d938d9d8d77 |
pam_sureidp.so |
Credential theft combined with local account takeover capabilities. |
da92fef44bc35bd1da5e8d6390ebd4619a2fec5986ca1e80f353923a41ad60df |
pam_kerb.so |
Hardcoded backdoor password bypassing normal authentication. |
819f91ff225f10500e94576a6473487162ffb5e50ec92dab9950b0b143418a21 |
pam_backdoor.so |
Grants privileged access using hardcoded root credentials. |
17fc68689d29cb90f9a5c406b2bbea052fa6edb8883d95843e4f5732915a29a1 |
pam_unix.so |
Trigger-based persistence through malicious udev rule injection. |
6a0d3236416e6d737b411c1226637f8d7e31e17cc1b6848398b8c46a56024350 |
get_ssh |
Steals PAM credentials and exfiltrates them to a C2 server. |
Created
July 30, 2026 13:56
-
-
Save pierrehpezier/a2aff6479ebe4003d81c4698e9b1336e to your computer and use it in GitHub Desktop.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment