# Group-IB reports Linux campaign that hid access behind cryptomining

_Published Wednesday, September 23, 2026 at 8:22 AM EDT · Security · Latest · Tier 2 — Notable_

![Group-IB reports Linux campaign that hid access behind cryptomining — Primary](https://jf.x.com/images/post/2102385369706909743.png)

Group-IB says attackers in a Linux campaign used cryptomining as cover while abusing Pluggable Authentication Module, the component that handles authentication, to retain access. The attackers also ran payloads that removed themselves from disk after execution, leaving less evidence for investigators.

The finding affects security teams that might close a cryptomining alert after removing the miner. Group-IB says the underlying problem is misuse of legitimate administrative access, which cannot be resolved by patching a software flaw alone.

## Sources

- [@GroupIB](https://x.com/GroupIB/status/2102385369706909743)

---
Canonical: https://techandbusiness.org/newswire/6Q2d9uO7tC5L1M3kEons88
Published: 2026-09-23T12:22:22.403Z
Story chronology: 2026-09-22T13:11:47.000Z
Retrieved: 2026-09-23T14:58:14.377Z
Publisher: Tech & Business (techandbusiness.org)
