“When a service tries to use PAM to authenticate a user, the malware checks the provided password against a hardcoded password,” he explained. ” If the password provided is a match, the hooked function returns a success response.”
https://threatpost.com/linux-malware-impossible-detect/179944/
I know of no linux servers which permit PAM authentication. Only a fool would allow it. Most servers use encrypted keys without root or password access. Most servers are also protected with Gateway or VPN on LAN subnets as well.