New Plague backdoor silently bypasses authentication controls to maintain stealthy SSH access to targeted Linux systems.

New Plague backdoor silently bypasses authentication controls to maintain stealthy SSH access to targeted Linux systems.

A sophisticated Linux backdoor, dubbed Plague, has recently emerged as a significant security concern for system administrators and cybersecurity professionals. Leveraging the trusted Pluggable Authentication Module (PAM) framework, Plague enables attackers to silently bypass authentication controls and maintain persistent SSH access to targeted Linux systems.
China’s CL-STA-0969 group is targeting Southeast Asian telecommunications networks.

China’s CL-STA-0969 group is targeting Southeast Asian telecommunications networks.

Since early 2024, major telecommunications organizations across Southeast Asia have faced attacks from an advanced state-sponsored cyber threat actor identified as CL-STA-0969. Security intelligence suggests a likely association with Chinese cyber-espionage operations, given the group’s methods and tools, which demonstrate a deep familiarity with telecommunications systems, high operational security, and technical adaptability.