Suspicious PAM Backdoor via pam_exec Configuration Change

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-05-11
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects modification of a PAM configuration file to load pam_exec.so, a pluggable authentication module backdoor described in Elastic Linux persistence research. By adding a pam_exec directive to an sshd PAM stack the attacker runs an arbitrary script on each authentication for persistence and credential capture. Edits to files under /etc/pam.d that introduce pam_exec are highly suspicious.

Related detections2 linkedT1556.003 — drag to rearrange
Suspicious Linux PAM Module pam_unix Modification via file_event
Malicious PAM Configuration Tampering for Passwordless su via pam_rootok (via process_creation)
Suspicious PAM Backdoor via pam_exec Configuration Change
Pivot detection · T1556.003 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.