MEDUSA

S1220

Malware.View on attack.mitre.org

About this malware

MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1014
Rootkit

MEDUSA is a rootkit with command execution and credential logging capabilities.

T1027.013
Encrypted/Encoded File

MEDUSA can XOR encrypt configuration strings.

T1563.001
SSH Hijacking

MEDUSA can be configured to capture SSH credentials via SSH hijacking.

T1574.006
Dynamic Linker Hijacking

MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library.

Groups that use it1

Campaigns1

References1

  1. Google Cloud Mandiant UNC3886 2024 Open source
    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.