Unmasked Origin: Infamous “OrBit” Linux Rootkit Exposed as a Fork of Open-Source Medusa
ID: 000ddaf4-537a-5bc8-8d34-b0ef51bb49b8
STIX ID: report--000ddaf4-537a-5bc8-8d34-b0ef51bb49b8
Feed Name: securityonline.info
Nicole at Intezer demonstrates that OrBit — initially reported as a bespoke Linux rootkit — is actually a weaponized fork of the open-source Medusa LD_PRELOAD rootkit. Deployed as a shared library that patches ld.so for system-wide persistence, OrBit provides a passive SSH backdoor, PAM credential harvesting and file hiding; it has split into a full and a lite lineage and has been adopted by multiple actors (including UNC3886 and BLOCKADE SPIDER) with recent samples adding active C2 and credential-forging capabilities via cron-based fetches (e.g., cf0.pw).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
