Plague
- Malware type
- backdoor, rootkit
- Family
- Malware family
- Last IoC activity
- 2026-06-26 08:37:28
- Profile updated
- 2026-07-07 14:28:36
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access.
Detection coverage
- 1 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_LNX_PLAGUE_BACKDOOR_Jul25 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Plague (report)
- nextron-systems.com — Plague A Newly Discovered Pam Based Backdoor For Linux (report)