logo

OrBit Rootkit Targets Linux to Steal SSH and Sudo Credentials

ID: 62bea056-aef0-5267-ba00-2d63597298d5

STIX ID: report--62bea056-aef0-5267-ba00-2d63597298d5

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Mayura Kathir

...
...

OrBit is a stealthy Linux rootkit (a repackaged Medusa LD_PRELOAD implant) actively observed 2022–2026 that hooks libc and PAM to harvest SSH and sudo credentials, hide files/processes/network activity, and provide a hidden SSH backdoor; operators have produced two lineages (A full-featured and B lightweight), added multi-stage droppers/infector behavior and limited C2 in later samples, and multiple threat groups (including ransomware-linked and state-backed actors) have reused the toolkit — IOCs (SHA256s) are provided for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.