Skip to content

Instantly share code, notes, and snippets.

@pierrehpezier
Created July 30, 2026 13:56
Show Gist options
  • Select an option

  • Save pierrehpezier/a2aff6479ebe4003d81c4698e9b1336e to your computer and use it in GitHub Desktop.

Select an option

Save pierrehpezier/a2aff6479ebe4003d81c4698e9b1336e to your computer and use it in GitHub Desktop.
SHA256 Name Description
01193b3f2299b6fa849824e6b3e7276d1b9d23c62dc06b9cefc31ade1bab5201 pam_unix.so Authentication bypass with hardcoded password and credential harvesting.
a60040a22cbb9db1a20dc2814249a7088f82fcb4fbc0fb1535c37700ee11c271 bd.bin Rust-based dropper deploying a PAM backdoor with C2 support.
99e69fe905fef0d4f0bac72ab55e6427163552c4972f1640e52ac9fccea66623 stooge1 Manual PAM symbol hijacking to steal plaintext credentials.
ccf20313c97946ac9b20a95486811b801113d7828d66b90a149813d79d5d8aca pam_backdoor.so Logs intercepted usernames and passwords to a hidden file.
c7022836a3f92a6589df7cce99ee3db69ce0a98a7c266ba90a8ec5e37227329e pam_backdoor.so Captures plaintext credentials and stores them for later retrieval.
5dc45286ff0904add55a4c2b286f0e79c7b880dfa21c6badbb5f814fefd7476e pam_backdoor.so Exfiltrates stolen credentials via outbound HTTP requests.
18e87a07ebb1995e1822e0609f221b13d3d86588b5575509fc085f0d385a905b pam_backdoor.so Stealthy credential harvesting while allowing normal authentication.
56d44489e8a4d17f59608730e90c2b24149c9cd9a6dd6bad1c709d938d9d8d77 pam_sureidp.so Credential theft combined with local account takeover capabilities.
da92fef44bc35bd1da5e8d6390ebd4619a2fec5986ca1e80f353923a41ad60df pam_kerb.so Hardcoded backdoor password bypassing normal authentication.
819f91ff225f10500e94576a6473487162ffb5e50ec92dab9950b0b143418a21 pam_backdoor.so Grants privileged access using hardcoded root credentials.
17fc68689d29cb90f9a5c406b2bbea052fa6edb8883d95843e4f5732915a29a1 pam_unix.so Trigger-based persistence through malicious udev rule injection.
6a0d3236416e6d737b411c1226637f8d7e31e17cc1b6848398b8c46a56024350 get_ssh Steals PAM credentials and exfiltrates them to a C2 server.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment