Hackers Use OrBit Rootkit to Steal Linux SSH and Sudo Credentials
ID: 6bc59fdf-1d22-541e-9bad-0a5203021e8e
STIX ID: report--6bc59fdf-1d22-541e-9bad-0a5203021e8e
Feed Name: Cyber Press
Threat Score
OrBit is a stealthy Linux rootkit—derived from the open-source Medusa project—deployed as an LD_PRELOAD shared library to hook 40+ system functions, exfiltrate SSH/sudo credentials, and hide files, processes, and network activity; researchers observed two lineages (A: full-featured with packet capture and auth forging, B: lightweight), active use by both the APT UNC3886 and cybercrime group BLOCKADE SPIDER, and multiple IOCs including SHA256 prefixes and varying installation paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
