Malware
3snake
3snake can be used to read and extract memory from sshd and sudo system calls which utilize password based authentication.
3snake is a Linux malware family.
Background
This tool harvests credentials by reading memory associated with sshd and sudo system calls that rely on password-based authentication. Rather than modifying the memory of the traced process, 3snake launches a separate process for each command, pulling out strings tied to password-based authentication.
Source: Malpedia (Fraunhofer FKIE).