Skip to content

// #dark-web

2 articles

🛡️ SecOps

PamDOORa: Linux Post-Exploitation PAM Module Backdoor Sold on Dark Web for $1,600

Flare.io researchers have identified PamDOORa, a commercially sold Linux backdoor sold for $1,600 on a Russian-language underground forum. PamDOORa installs as a malicious PAM (Pluggable Authentication Module) on compromised Linux systems, creating a persistent hidden SSH access mechanism that activates via a magic password and a TCP port — while also harvesting the credentials of all legitimate users who authenticate to the system.

#linux +8
🗄️ Assets

ShinyHunters Claims Breaches at Zara, Carnival, and 7-Eleven — Extortion Deadline Set

Prolific threat actor ShinyHunters posted simultaneous claims of data theft from Inditex/Zara, Carnival Corporation, and 7-Eleven on dark web forums on 21 April, threatening to publish stolen datasets. None of the companies has confirmed the breaches. Given ShinyHunters' track record, claims should be treated as credible pending investigation.

#data-breach +6