Researchers reported a covert Linux cryptomining campaign that gained access through a trusted third-party connection, escalated privileges to root, and then abused Pluggable Authentication Modules (PAM) to move into low-privileged accounts without passwords. The operators reportedly used pam_rootok with su, disabled or suppressed logging, altered authentication records, and planted redundant cron-based persistence across less-monitored user accounts to preserve access and complicate remediation. Group-IB linked the activity to the V25 Generation 26 campaign family.
The payload was described as a heavily modified, self-unlinking XMRig 6.25.0 implant that ran from memory, used /tmp/.lock as a mutex, and spoofed process names such as ssh to evade detection. Researchers said the miner optimized execution with CPU-aware worker spawning, MSR interaction, and Huge Pages, while disguising Stratum mining traffic with a fake Java Agent user agent string to blend into normal network activity. Published indicators included the domain unable[.]download, campaign identifier My-V25-GEN-26, and multiple malware hashes tied to the implant.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Group-IB decoded obfuscated configuration data from the modified, memory-resident XMRig 6.25.0 implant and linked it to the V25 (Generation 26) campaign family. The analysis revealed identifiers and infrastructure including unable.download, My-V25-GEN-26, and the mutex file /tmp/.lock, along with published indicators and hashes.
In May 2026, researchers identified a covert Monero cryptomining campaign targeting Linux systems via a trusted third-party access path, followed by privilege escalation to root. The operators abused PAM, specifically pam_rootok with su, to move into low-privileged accounts and establish redundant cron-based persistence while suppressing logs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.