{"repo":"ldpreload/Medusa","free":true,"listed":false,"github":"https://github.com/ldpreload/Medusa","clone":"git clone https://github.com/ldpreload/Medusa.git","description":"LD_PRELOAD Rootkit","language":"C","stars":331,"topics":["backdoor","ldpreload","linux","malware","rootkit"],"license":null,"category":"dev-tools","readme_excerpt":"Paralyze resistance with persistence. &lceil; Description &rceil; Medusa is a powerful, stealthy, versatile, and, modular rootkit designed to give attackers complete control over Linux systems. Medusa is compiled and ready to be executed as a small ELF executable file, which no means extra building or configuration requirements! Medusa is larger than a few hundred kilobytes in size. Once installed, the rootkit sets up a dynamic linker that modifies the way applications are loaded and executed on the system. At this point the Medusa hooks a plethora of API system calls, library functions and signal handlers to achieve imbreakable and uninterceptable persistence. Medusa intercepts a plethoa of system calls made by all applications on the Medusa infected machine.. Hooking these system calls allows a Medusa to control and modify the behavior when system call is made. For example, with stat() family calls, a user can specify what information should be returned when those calls are made, or make changes to the permissions of files and directories. With access() , the user can control who has permission to what areas of the system. With write() , read() , open() , and their derivatives, Medusa can control what files and directories are accessed by the system, and what data is written to them. Truncate and chmod() / chown() allows for control over how files and directories are manipulated. Pututxline, updwtmp, and pututline are used for managing user logins and account information. &","default_branch":null,"files":null,"tree":[],"storefront":"/r/ldpreload","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ldpreload/Medusa/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}