×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research: Botnet Ebury is active and growing. 400 thousand violated Linux servers for cryptocurrency theft and profitless purpose

Customer Press Room

ESET Research: Botnet Ebury is active and growing. 400 thousand violated Linux servers for cryptocurrency theft and profitless purpose

by Grandangolo Communications / Friday, 31 May 2024 / Published in Eset

An investigation into one of the most advanced server-side malware campaigns has been published. In many cases, Ebury operators have gained access to servers of ISPs and well-known hosting providers

ESET, the global European cybersecurity market leader, has published an in-depth investigation into one of the world's most advanced and growing server-side malware campaigns, which has seen hundreds of thousands of servers compromised over at least 15 years of operation. The infamous Ebury Group and its botnet have been responsible for various illicit activities over the years, including spreading spam, redirecting web traffic, and stealing credentials. Recently, they have focused on credit card and cryptocurrency theft. Additionally, Ebury was used as a backdoor to compromise nearly 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised at the end of 2023. In many cases, Ebury operators managed to gain full access to servers of Internet Service Providers (ISPs) and well-known hosting providers.

Ten years ago, ESET published a white paper on Operation Windigo, which describes the use of several malware families working together, with Ebury at the center. In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Dutch National Police, requested ESET's cooperation regarding servers in the Netherlands that were suspected to have been compromised with the Ebury malware. These suspicions proved to be true, and with the assistance of the NHTCU, ESET Research gained significant visibility into the operations conducted by the Ebury threat actors.

“Following the publication of the Windigo white paper in early 2014, one of the authors was arrested at the Finnish-Russian border in 2015 and subsequently extradited to the United States. Although he initially declared himself innocent, he admitted guilt to the charges in 2017, a few weeks before the trial took place in the U.S. District Court in Minneapolis, in which ESET researchers were scheduled to testify,” says Marc-Etienne M. Léveillé, the ESET researcher who has been investigating Ebury for more than a decade.

Ebury, active since at least 2009, is an OpenSSH backdoor and credential stealer. It is used to deploy additional malware to: monetize the botnet (such as web traffic redirection modules), proxy traffic for spam, perform adversary-in-the-middle (AitM) attacks, and host supporting malicious infrastructure. In AitM attacks, ESET observed more than 200 targets on over 75 networks in 34 different countries between February 2022 and May 2023.

The Ebury botnet was used to steal cryptocurrency wallets, credentials and credit card data. ESET has discovered new malware families created and distributed by the for-profit gang, including Apache modules and a kernel module to perform web traffic redirection. Ebury operators also used zero-day vulnerabilities in administration software to compromise servers en masse.

Once a system is compromised, data of various types is exfiltrated. Using passwords and access keys obtained on that system, the credentials are reused to attempt to access related systems. Each new major release of Ebury introduces some important changes and new obfuscation features and techniques.

"We have documented situations in which hosting providers' infrastructure was compromised by Ebury. In these cases, Ebury was installed on servers rented by the providers, without the tenants being informed. This allowed the Ebury perpetrators to compromise thousands of servers at once," says Léveillé. Ebury has no geographical borders: there are servers hacked with Ebury in almost every country in the world. Every time a hosting provider was compromised, it spawned a large number of compromised servers in the same data centers.

At the same time, no sector appears to be more targeted than others. Victims range from universities, small and large businesses, to Internet Service Providers, cryptocurrency traders, Tor loop nodes, shared hosting providers, and dedicated server providers, to name a few.

At the end of 2019, the infrastructure of a large and popular building was compromised registrar domain and web hosting providers based in the United States. In total, the attackers breached approximately 2,500 physical servers and 60,000 virtual servers. Most, if not all, of these servers are shared by multiple users to host the websites of more than 1.5 million accounts. In another incident dating back to 2023, around 70,000 servers from the same hosting provider were compromised by Ebury. Kernel.org, which hosts the Linux kernel source code, is also among the victims of Ebury.

"Ebury represents a serious threat and challenge to the Linux community. There is no simple solution to make it ineffective, but a number of mitigations can be applied to minimize its spread and impact. It must be clear that the problem does not only concern organizations or individuals who care little about security, but also tech experts and large organizations," concludes Léveillé.

For more technical information and a variety of tools and indicators to help system administrators determine whether their systems are compromised by Ebury, see the full white paper “Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain”.

Tagged under: Ebury, Eset, Linux

About Grandangolo Communications

What you can read next

ESET Research: Lazarus Group Targets Europe's Drone Industry for Espionage Activities
ESET receives the Top Product award for best Windows antivirus software from AV-TEST
ESET introduces a new range of products for Telcos and ISPs

Customer Press Room

  • Arrow Electronics has been awarded by Equinix as Distributor of the Year 2025 for the EMEA region

    Arrow Electronics, a global supplier of technology...
  • SentinelOne makes the Purple AI Agentic Investigation solution available to all customers, bringing the latest generation AI directly into the SOC

    The investigations, started autonomously and without need...
  • Acronis TRU reveals the ongoing evolution of the INC ransomware group

    A recent report published by Acronis Threat ...
  • ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools

    The Gentlemen Group develops, maintains and supplies...
  • Imprivata presents the Agentic Identity Management solution to protect and govern the access of AI agents

    Imprivata, a leading company in Ac...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP