Linux Cryptominer Impersonates Standard Users to Evade Detection
A Monero cryptomining campaign is abusing Linux PAM to shift activity from root to low-privileged accounts, reducing the likelihood of triggering SOC alerts. After gaining root access through a trusted third party, attackers used pam_rootok, distributed cron-based persistence across multiple accounts, disabled logging, and disguised mining processes as legitimate services. The modified XMRig 6.25.0 miner deletes its executable after launch, runs in memory, conceals network traffic, and optimizes system resources for mining. Organizations should forward logs to tamper-resistant external storage, restrict third-party access, and monitor memory and transient artifacts such as /tmp/.lock.
Reference: infosecurity-magazine.com