Ebury

MITRE ATT&CK: S0377 View on attack.mitre.org

Aliases: Ebury

First seen
2009-01-01 00:00:00
Malware type
backdoor, botnet, credential-stealer
Family
Malware family
Operating systems
linux
Related IoCs
2 (2 malicious)
Last IoC activity
2026-09-02 12:35:25
Profile updated
2026-07-07 14:24:22

Targeted industries: technology-and-telecommunications financial-services

Context

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Ebury (S0377). The 2 most recently updated:

TypeIndicatorUpdatedSources
hostname awsrsznmdb.biz 2026-09-02 1
file sample JaffaCakes118_3c37ea602200831089d37bcb6b567476 2026-07-18 1

Detection coverage

  • 1 YARA rules
  • 334 Sigma rules

Malware & tools used

  • Rootkit (attack-pattern)
  • Unix Shell (attack-pattern)
  • Pluggable Authentication Modules (attack-pattern)
  • DNS (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Modify Authentication Process (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Disable or Modify Linux Audit System Log (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Python (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Shared Modules (attack-pattern)
  • Code Signing (attack-pattern)
  • Private Keys (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)

Used by threat actors

Detection rules

  • ESET_Ebury_V1_7_Crypto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Ebury (report)
  • ESET — Operation Windigo (report)
  • ESET — An In Depth Analysis Of Linuxebury (report)
  • web-assets.esetstatic.com — Ebury Is Alive But Unseen (report)
  • acn.gov.it — Csirt Italiano Windigo Ebury Variant (report)
  • ESET — Dark Side Of The Forsshe (report)
  • ESET — Operation Windigo Good Job Eset Says Malware Author (report)
  • ESET — Ebury Alive Unseen 400K Linux Servers Compromised Cryptotheft Financial Gain (report)
  • ESET — Eset The Dark Side Of The Forsshe (report)
  • justice.gov — Russian Citizen Pleads Guilty Involvement Global Botnet Conspiracy (report)
  • csirt.gov.it — Download (report)
  • ESET — Windigo Ebury Update 2 (report)
  • security.web.cern.ch — Windigo.Shtml (report)
  • MITRE ATT&CK — S0377 (report)
  • bleepingcomputer.com — Russian Hacker Pleads Guilty For Role In Infamous Linux Ebury Malware (report)

External references