Skip to content

Orbit

OrBit is a Linux userland rootkit and backdoor derived from the publicly available Medusa rootkit codebase.

Profile source: Mallory opens in a new tab

Orbit

Family profile

OrBit is a Linux userland rootkit and backdoor derived from the publicly available Medusa rootkit codebase. It is deployed as a malicious shared library and achieves system-wide execution by abusing dynamic-linker preload configuration; variants can additionally patch the dynamic linker itself, enabling redundant persistence and restoration of one mechanism if the other is removed. OrBit has targeted Linux servers, cloud infrastructure, and virtualization environments.

The rootkit hooks numerous libc, PAM, libcap, and libpcap functions to conceal files, directories, processes, library mappings, network connections, and backdoor traffic from common utilities and packet-capture tooling. It intercepts SSH and sudo-related authentication activity to collect credentials, and full-featured variants implement PAM hooks that permit attacker-controlled authentication outcomes and remote SSH access. Its installer can deploy persistent or volatile payloads and has included mechanisms to elevate users to root. Later activity incorporated an infector-dropper chain with cron-based retrieval of updated payloads.

Multiple distinct threat clusters have used OrBit or closely matching Medusa-derived builds, including UNC3886 and BLOCKADE SPIDER; a separate 2025 activity cluster shared tooling and infrastructure characteristics with the RHOMBUS botnet ecosystem. Observed builds include a feature-rich lineage and a reduced-feature lineage that omitted some credential interception and network-hiding functions.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 28, 2026
Last activity
Sep 28, 2026
Feed role
C2 / Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Redoubt Networks1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

2 named in public reporting
UNC3886

A dangerous rootkit called OrBit has been quietly targeting Linux systems for years, stealing login credentials and hiding deep inside infected machines without triggering most security tools.

Blockade Spider

A dangerous rootkit called OrBit has been quietly targeting Linux systems for years, stealing login credentials and hiding deep inside infected machines without triggering most security tools.

MITRE ATT&CK

Orbit in ATT&CK

18 distinct techniques

Reporting

Research mentioning Orbit

Jul 25
Palo Alto Networks Unit 42

Muddled Libra Threat Assessment: Further-Reaching, Faster, More Impactful

Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption. Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.

Oct 19
Dfir

bedevil: Dynamic Linker Patching | dfir.ch

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.