Plague

Malware type
backdoor, rootkit
Family
Malware family
Last IoC activity
2026-06-26 08:37:28
Profile updated
2026-07-07 14:28:36

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_LNX_PLAGUE_BACKDOOR_Jul25 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Plague (report)
  • nextron-systems.com — Plague A Newly Discovered Pam Based Backdoor For Linux (report)

External references