Researchers reported that the Linux rootkit OrBit is not a distinct malware family but a modified deployment of the open-source Medusa LD_PRELOAD rootkit published on GitHub. Active from 2022 through early 2026, OrBit achieves persistence by forcing a malicious shared library into processes through dynamic linker configuration, hooks more than 40 functions to hide its presence, and harvests credentials from SSH and sudo activity while storing stolen data in hidden paths such as /lib/libseconf/. Investigators identified two build lineages: Lineage A, which preserved the full credential-theft and stealth feature set, and Lineage B, a reduced variant that dropped PAM interception, packet capture, and TCP port hiding before disappearing after 2024.
The malware expanded in 2025 with a pam_sm_authenticate hook that can alter authentication outcomes, along with a two-stage infector and dropper chain that used cron-based retrieval from external infrastructure including cf0[.]pw, the first observed OrBit-related component with direct outbound communications. Researchers linked separate deployments of the same codebase to at least three threat clusters, including UNC3886, BLOCKADE SPIDER, and a 2025 campaign sharing tooling and infrastructure traits with the RHOMBUS botnet. Detection guidance highlighted recurring Medusa artifacts such as sshpass.txt, .logpam, and /etc/cron.hourly/0, as well as YARA-based identification of the malware’s XOR-encoded string table across renamed variants.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
On May 14, 2026, Intezer published research concluding that OrBit is a repackaged and selectively configured build of the open-source Medusa rootkit. The report documented two main lineages, evolving features, infrastructure changes, and detection artifacts.
Analysis connected different OrBit/Medusa deployments to at least three actor clusters, including UNC3886, BLOCKADE SPIDER, and a 2025 campaign sharing tooling and infrastructure traits with the RHOMBUS botnet ecosystem. This attribution showed the same codebase was reused by multiple unrelated operators.
During 2025, one operator introduced a two-stage infector and dropper workflow that retrieved payloads via cron from external infrastructure including cf0[.]pw. Researchers described this as the first observed OrBit-related component with direct external communications.
In 2025, OrBit operators added a pam_sm_authenticate hook that could manipulate authentication outcomes and support service-side impersonation. This marked a significant capability increase in the malware's evolution.
Researchers identified a lighter OrBit branch, Lineage B, that removed features such as PAM interception, packet capture, and TCP port hiding. This lineage was no longer observed after 2024.
From 2022 onward, operators used modified Medusa builds later tracked as OrBit on Linux systems. These variants persisted via dynamic linker configuration, hooked dozens of functions, and harvested SSH and sudo credentials.
The publicly available Medusa Linux userland rootkit was released on GitHub in December 2022. Later analysis concluded OrBit was built from this codebase rather than being a wholly distinct malware family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceintezer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.