Ebury
MITRE ATT&CK: S0377 View on attack.mitre.org
Aliases: Ebury
- First seen
- 2009-01-01 00:00:00
- Malware type
- backdoor, botnet, credential-stealer
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-09-02 12:35:25
- Profile updated
- 2026-07-07 14:24:22
Targeted industries: technology-and-telecommunications financial-services
Context
Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Ebury (S0377). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | awsrsznmdb.biz | 2026-09-02 | 1 |
| file sample | JaffaCakes118_3c37ea602200831089d37bcb6b567476 | 2026-07-18 | 1 |
Detection coverage
- 1 YARA rules
- 334 Sigma rules
Malware & tools used
- Rootkit (attack-pattern)
- Unix Shell (attack-pattern)
- Pluggable Authentication Modules (attack-pattern)
- DNS (attack-pattern)
- Fallback Channels (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Modify Authentication Process (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Disable or Modify Linux Audit System Log (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Standard Encoding (attack-pattern)
- Python (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Shared Modules (attack-pattern)
- Code Signing (attack-pattern)
- Private Keys (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
Used by threat actors
- Windigo (threat-actor)
Detection rules
- ESET_Ebury_V1_7_Crypto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Ebury (report)
- ESET — Operation Windigo (report)
- ESET — An In Depth Analysis Of Linuxebury (report)
- web-assets.esetstatic.com — Ebury Is Alive But Unseen (report)
- acn.gov.it — Csirt Italiano Windigo Ebury Variant (report)
- ESET — Dark Side Of The Forsshe (report)
- ESET — Operation Windigo Good Job Eset Says Malware Author (report)
- ESET — Ebury Alive Unseen 400K Linux Servers Compromised Cryptotheft Financial Gain (report)
- ESET — Eset The Dark Side Of The Forsshe (report)
- justice.gov — Russian Citizen Pleads Guilty Involvement Global Botnet Conspiracy (report)
- csirt.gov.it — Download (report)
- ESET — Windigo Ebury Update 2 (report)
- security.web.cern.ch — Windigo.Shtml (report)
- MITRE ATT&CK — S0377 (report)
- bleepingcomputer.com — Russian Hacker Pleads Guilty For Role In Infamous Linux Ebury Malware (report)