Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems
ID: a7960f56-d6d5-5e94-aa8d-acbe35a774a3
STIX ID: report--a7960f56-d6d5-5e94-aa8d-acbe35a774a3
Feed Name: cybersecurityNews.com
OrBit is a persistent, highly stealthy Linux rootkit based on the publicly released Medusa source that hooks dozens of system functions to hide itself and capture SSH/sudo credentials; it has multiple lineages (A and B), has been active from 2022–2026, and is being reused by at least three distinct operator groups (including a state-sponsored actor and criminal actors). The report provides extensive IoCs (SHA256 hashes, domains, IPs, file paths and filenames), details on delivery and persistence mechanisms (including a 2025 two-stage infector and cron-based fetch), and detection guidance such as YARA rules and artifact filenames to monitor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
