logo

Ebury botnet malware infected 400,000 Linux servers since 2009

ID: 41990149-64a7-5776-af52-773b80eefc6d

STIX ID: report--41990149-64a7-5776-af52-773b80eefc6d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ESET reports that the Ebury Linux botnet has compromised roughly 400,000 Linux servers since 2009 (about 100,000 still infected as of late 2023). Operators target hosting providers and their clients via credential stuffing and supply-chain techniques, steal SSH keys and intercept SSH traffic using ARP spoofing, and deploy kernel- and user-space modules (DGA-enabled, obfuscated) to exfiltrate credentials, redirect traffic, send spam, and steal cryptocurrency and payment data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.