Suspicious Linux PAM Module pam_unix Modification via file_event

PremiumReviewedSigma · Medium · v1
Product
linux
Category
file_event
Author
HuntRule
Published
2026-08-02
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation or modification of the pam_unix.so authentication module that malware replaces to log SSH passwords or accept a universal backdoor password. Unit 42 documented Linux malware tampering with pam_unix.so and related PAM shared objects to subvert authentication, so unexpected writes to this module warrant investigation.

Related detections2 linkedT1556.003 — drag to rearrange
Malicious PAM Configuration Tampering for Passwordless su via pam_rootok (via process_creation)
Suspicious PAM Backdoor via pam_exec Configuration Change
Suspicious Linux PAM Module pam_unix Modification via file_event
Pivot detection · T1556.003 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.