CERT Polska warns that MikroTik routers with SSH exposed to the internet are being hijacked without any authentication.
The Pamdoora backdoor targets Linux authentication modules to silently record SSH passwords and maintain persistent remote access.