New Linux Malware Infects All Running Processes


OrBit provides attackers with remote access over SSH.

Security researchers from Intezer have reported a new Linux malware variant called OrBit.

“The malware implements advanced evasion techniques and gains persistence on the machine by hooking key functions, provides the threat actors with remote access capabilities over SSH, harvests credentials, and logs TTY commands,” reports Nicole Fishbein.

OrBit steals information from different commands and utilities and stores it in specific files on the machine. Once the malware is installed, it will infect all processes running on the machine. 

Technical details about how OrBit works are available from Intezer.


Related content

comments powered by Disqus