Thousands of Linux servers infected by Ebury malware

Computer programming code. Programming code abstract technology background of software developer and Computer script.
(Image credit: Shutterstock/BEST-BACKGROUNDS)

Thousands of Linux servers are still infected by Ebury, a decades-old information-stealing malware that was thought extinct, experts have warned.

Ebury is a sophisticated piece of malware designed to compromise Linux-based systems, particularly servers. It's a type of backdoor and credential-stealing malware that allows attackers to gain unauthorized access to compromised systems.

Ebury's developers are financially motivated, in newer times expanding into the cryptocurrency space, as well. Ebury also seems to be used for spam and web traffic redirection.

Targeting hosting providers

When cybersecurity researchers from ESET first reported on Ebury a decade ago, the report resulted in the arrest of the malware’s operators. However, that didn’t stop the malware from being updated and growing in the years since. Cumulatively, since 2009, some 400,000 Linux-powered servers have been infected by this backdoor. 

At the end of last year, more than 100,000 endpoints were thought to still carrying the infection, according to a follow-up report (PDF) that ESET published earlier this week.

Key Ebury victims seem to be hosting providers, the researchers found. “The gang leverages its access to the hosting provider’s infrastructure to install Ebury on all the servers that are being rented by that provider,” they explained. As part of an experiment, they rented a virtual server and suffered an infection within a week. 

“Another interesting method is the use of adversary in the middle to intercept SSH traffic of interesting targets inside data centers and redirect it to a server used to capture credentials,” they added.

Last year, more than 200 servers were targeted by Ebury operators. Among the targets were many Bitcoin and Ethereum nodes, as one of Ebury’s main features was to automatically steal cryptocurrency wallets hosted on the targeted server, as soon as the victim logs in with a password.

Via BleepingComputer

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
China
Chinese hackers develop effective new hacking technique to go after business networks
Ransomware
Researchers hijack thousands of backdoors thanks to expired domains
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does