logo

Unmasked Origin: Infamous “OrBit” Linux Rootkit Exposed as a Fork of Open-Source Medusa

ID: 000ddaf4-537a-5bc8-8d34-b0ef51bb49b8

STIX ID: report--000ddaf4-537a-5bc8-8d34-b0ef51bb49b8

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

Nicole at Intezer demonstrates that OrBit — initially reported as a bespoke Linux rootkit — is actually a weaponized fork of the open-source Medusa LD_PRELOAD rootkit. Deployed as a shared library that patches ld.so for system-wide persistence, OrBit provides a passive SSH backdoor, PAM credential harvesting and file hiding; it has split into a full and a lite lineage and has been adopted by multiple actors (including UNC3886 and BLOCKADE SPIDER) with recent samples adding active C2 and credential-forging capabilities via cron-based fetches (e.g., cf0.pw).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.