⤷ Title: Unmasked Origin: Infamous “OrBit” Linux Rootkit Exposed as a Fork of Open-Source Medusa
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 09:22:30 +0000
════════════════════════
⌗ Tags: #Malware #BLOCKADE SPIDER #infosec #Intezer #LD_PRELOAD #Linux Security #Medusa Malware #OrBit Rootkit #PAM Hooking #Pluggable Authentication Modules #UNC3886 #userland rootkit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 09:22:30 +0000
════════════════════════
⌗ Tags: #Malware #BLOCKADE SPIDER #infosec #Intezer #LD_PRELOAD #Linux Security #Medusa Malware #OrBit Rootkit #PAM Hooking #Pluggable Authentication Modules #UNC3886 #userland rootkit
Daily CyberSecurity
Unmasked Origin: Infamous "OrBit" Linux Rootkit Exposed as a Fork of Open-Source Medusa
New research by Intezer reveals the OrBit Linux rootkit is actually a fork of the open-source Medusa kit, actively weaponized across multiple APTs.