A cryptomining operation is deliberately avoiding root access on compromised Linux servers, instead impersonating low-privileged users to bypass security alerts, as reported by Infosecurity Magazine.The campaign, identified in May 2026 by Group-IB, uses a modified XMRig miner. After gaining initial access through a third-party relationship and escalating to root, attackers abuse Linux Pluggable Authentication Modules (PAM) to assume the identities of standard accounts without needing passwords. This tactic creates a "forensic smokescreen" by scattering activity and persistence mechanisms across unmonitored accounts. The attackers also disable core logging services and tamper with authentication logs, leaving minimal traces of their actions.To further evade detection, the malware employs process masquerading, spoofing legitimate process names like "ssh", and uses a Java/Agent user agent for its mining traffic to blend in with normal web application flows. The implant deletes its own binary from disk after execution, residing entirely in memory, which circumvents conventional disk scans. It also terminates competing miners and uses layered XOR keys to conceal its configuration. Researchers recommend forwarding logs in real-time to an external, tamper-proof system and hunting for transient artifacts like mutexes to detect such sophisticated threats.Source: Infosecurity Magazine
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds




