logo

Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems

ID: a7960f56-d6d5-5e94-aa8d-acbe35a774a3

STIX ID: report--a7960f56-d6d5-5e94-aa8d-acbe35a774a3

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

OrBit is a persistent, highly stealthy Linux rootkit based on the publicly released Medusa source that hooks dozens of system functions to hide itself and capture SSH/sudo credentials; it has multiple lineages (A and B), has been active from 2022–2026, and is being reused by at least three distinct operator groups (including a state-sponsored actor and criminal actors). The report provides extensive IoCs (SHA256 hashes, domains, IPs, file paths and filenames), details on delivery and persistence mechanisms (including a 2025 two-stage infector and cron-based fetch), and detection guidance such as YARA rules and artifact filenames to monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.