ThreatCluster

OrBit Rootkit Exploits Linux Systems to Steal Credentials

First seen 15 May 2026, 13:56 UTC GbhackersCybersecuritynews 96% similarity 67

Article Content

Browse articles
ThreatCluster

The OrBit rootkit has been targeting Linux systems for several years, specifically harvesting SSH and sudo credentials. Initially thought to be a custom threat, it has been identified as a modified version of a publicly available rootkit. Research indicates that OrBit has evolved significantly since it was first analyzed in 2022. The rootkit operates stealthily, evading detection by most security tools, and has been spreading globally. Affected systems include various Linux distributions, with the attack vector primarily being the hijacking of userland processes. The current status shows that OrBit remains active in the wild, posing a significant risk to Linux environments. Security professionals are urged to enhance their defenses against this ongoing threat.

Key Points: • OrBit rootkit targets Linux systems to steal SSH and sudo credentials. • Initially believed to be custom-built, it is a modified version of a public rootkit. • The threat has been active for years and continues to evolve without detection.

ThreatCluster AI

Timeline

2022-01-01
OrBit rootkit first analyzed
Initial research identified OrBit as a Linux userland rootkit, believed to be custom-built.
Gbhackers
2026-05-15
New research reveals OrBit's evolution
Recent findings show OrBit has evolved over four years while remaining active and undetected.
Cybersecuritynews
2026-05-15
OrBit rootkit continues to spread globally
The rootkit has been identified as a significant threat to Linux systems worldwide, affecting numerous distributions.
Gbhackers

Community

Browse all →

Tracked Entities in This Story