An investigation into one of the most advanced server-side malware campaigns has been published. In many cases, Ebury operators have gained access to servers of ISPs and well-known hosting providers
ESET, the global European cybersecurity market leader, has published an in-depth investigation into one of the world's most advanced and growing server-side malware campaigns, which has seen hundreds of thousands of servers compromised over at least 15 years of operation. The infamous Ebury Group and its botnet have been responsible for various illicit activities over the years, including spreading spam, redirecting web traffic, and stealing credentials. Recently, they have focused on credit card and cryptocurrency theft. Additionally, Ebury was used as a backdoor to compromise nearly 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised at the end of 2023. In many cases, Ebury operators managed to gain full access to servers of Internet Service Providers (ISPs) and well-known hosting providers.
Ten years ago, ESET published a white paper on Operation Windigo, which describes the use of several malware families working together, with Ebury at the center. In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Dutch National Police, requested ESET's cooperation regarding servers in the Netherlands that were suspected to have been compromised with the Ebury malware. These suspicions proved to be true, and with the assistance of the NHTCU, ESET Research gained significant visibility into the operations conducted by the Ebury threat actors.
“Following the publication of the Windigo white paper in early 2014, one of the authors was arrested at the Finnish-Russian border in 2015 and subsequently extradited to the United States. Although he initially declared himself innocent, he admitted guilt to the charges in 2017, a few weeks before the trial took place in the U.S. District Court in Minneapolis, in which ESET researchers were scheduled to testify,” says Marc-Etienne M. Léveillé, the ESET researcher who has been investigating Ebury for more than a decade.
Ebury, active since at least 2009, is an OpenSSH backdoor and credential stealer. It is used to deploy additional malware to: monetize the botnet (such as web traffic redirection modules), proxy traffic for spam, perform adversary-in-the-middle (AitM) attacks, and host supporting malicious infrastructure. In AitM attacks, ESET observed more than 200 targets on over 75 networks in 34 different countries between February 2022 and May 2023.
The Ebury botnet was used to steal cryptocurrency wallets, credentials and credit card data. ESET has discovered new malware families created and distributed by the for-profit gang, including Apache modules and a kernel module to perform web traffic redirection. Ebury operators also used zero-day vulnerabilities in administration software to compromise servers en masse.
Once a system is compromised, data of various types is exfiltrated. Using passwords and access keys obtained on that system, the credentials are reused to attempt to access related systems. Each new major release of Ebury introduces some important changes and new obfuscation features and techniques.
"We have documented situations in which hosting providers' infrastructure was compromised by Ebury. In these cases, Ebury was installed on servers rented by the providers, without the tenants being informed. This allowed the Ebury perpetrators to compromise thousands of servers at once," says Léveillé. Ebury has no geographical borders: there are servers hacked with Ebury in almost every country in the world. Every time a hosting provider was compromised, it spawned a large number of compromised servers in the same data centers.
At the same time, no sector appears to be more targeted than others. Victims range from universities, small and large businesses, to Internet Service Providers, cryptocurrency traders, Tor loop nodes, shared hosting providers, and dedicated server providers, to name a few.
At the end of 2019, the infrastructure of a large and popular building was compromised registrar domain and web hosting providers based in the United States. In total, the attackers breached approximately 2,500 physical servers and 60,000 virtual servers. Most, if not all, of these servers are shared by multiple users to host the websites of more than 1.5 million accounts. In another incident dating back to 2023, around 70,000 servers from the same hosting provider were compromised by Ebury. Kernel.org, which hosts the Linux kernel source code, is also among the victims of Ebury.
"Ebury represents a serious threat and challenge to the Linux community. There is no simple solution to make it ineffective, but a number of mitigations can be applied to minimize its spread and impact. It must be clear that the problem does not only concern organizations or individuals who care little about security, but also tech experts and large organizations," concludes Léveillé.
For more technical information and a variety of tools and indicators to help system administrators determine whether their systems are compromised by Ebury, see the full white paper “Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain”.






