Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 Years
ID: 2d9fde94-628f-5d5f-96d2-ec74bd38e615
STIX ID: report--2d9fde94-628f-5d5f-96d2-ec74bd38e615
Feed Name: The Hacker News
**Ebury** is a long-running, highly modular Linux server botnet that ESET attributes to large-scale financially motivated operations, estimated to have compromised ~400,000 servers since 2009 (with >100,000 still infected as of late 2023). The malware operates as an OpenSSH backdoor and credential stealer, includes userland rootkit and kernel components, a DGA and obfuscation, and deploys Apache modules and a KernelRedirect Netfilter hook to perform server-side web skimming, traffic redirection, spam, and cryptocurrency theft; delivery vectors include SSH credential theft, AitM, credential stuffing, and exploitation of hosting control panel vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
