
XMRig Botnet Abuses Linux PAM to Hide Root Activity and Persist Across Accounts
A stealthy Monero (XMR) cryptomining campaign uncovered in May 2026 is leveraging Linux Pluggable Authentication Modules (PAM) to evade detection, maintain persistence, and obscure root-level activity across compromised environments. The operation highlights growing risks from supply chain compromises and the increasing sophistication of fileless malware targeting Linux infrastructure. The intrusion began through a trusted third-party […]
The post XMRig Botnet Abuses Linux PAM to Hide Root Activity and Persist Across Accounts appeared first on Cyber Security News.