Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access

A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tracked as part of the V25 (Generation 26) campaign family, demonstrates a mature blend of supply chain abuse, PAM weaponization, and […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: