logo

400K Linux Servers Recruited by Resurrected Ebury Botnet

ID: 7ed1c04f-a4c8-51f5-b1d3-417bba34ad90

STIX ID: report--7ed1c04f-a4c8-51f5-b1d3-417bba34ad90

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-05-17

Date Updated: 2026-04-21

Author: John Leyden, Contributing Writer

...
...

Ebury is a long-lived OpenSSH backdoor botnet that has backdoored nearly 400,000 Linux, FreeBSD, and OpenBSD servers (with 100,000+ still compromised as of late 2023). Operators use credential theft, zero-day server software exploits, and credential reuse to spread across hosting providers and data centers, deploy secondary modules (HTTP backdoors, spam bots), and intercept SSH sessions to steal cryptocurrency wallets and credit card data; ESET published updated research, detection/remediation tools, and ongoing law-enforcement collaboration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.