logo

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

ID: 9de73c14-e42e-55c7-bcbc-34d668799882

STIX ID: report--9de73c14-e42e-55c7-bcbc-34d668799882

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2024-05-14

Date Updated: 2026-05-01

...
...

ESET researchers report that the Ebury campaign continues to compromise hundreds of thousands of Linux servers (≈400,000 historical, >100,000 active as of late 2023) using an OpenSSH backdoor, credential stealing, ARP spoofing AiTM attacks, and additional malware families to steal cryptocurrency and financial data; the threat has evolved with obfuscation, a new DGA, and a userland rootkit, and ESET provides IOCs and detection resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.