Malware.View on attack.mitre.org
MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
MEDUSA is a rootkit with command execution and credential logging capabilities. |
| T1027.013 Encrypted/Encoded File |
MEDUSA can XOR encrypt configuration strings. |
| T1563.001 SSH Hijacking |
MEDUSA can be configured to capture SSH credentials via SSH hijacking. |
| T1574.006 Dynamic Linker Hijacking |
MEDUSA can execute code through dynamic linker hijacking of the `LD_PRELOAD` library. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.