Ebury

Malware

⚠️ Overview

Ebury is a Linux/Unix backdoor and credential-stealing malware first discovered in 2011 by ESET researchers, linked to a Russian-speaking threat group tracked as the Windigo operation (also known as Ebury Group). It is classified as a server-side backdoor with stealthy persistence capabilities, primarily targeting dedicated and virtual private servers to harvest SSH credentials and enable spam relay or network reconnaissance.

🔧 Technical Capabilities

Ebury propagates via weak SSH credentials, exploiting default or brute-forced passwords, and installs a modified version of the libkeyutils.so or libpam shared library to intercept plaintext SSH passwords from both incoming and outgoing connections. It uses a custom kernel-level rootkit (tty-related hooking) to hide its processes and network connections, persisting through system updates by patching the OpenSSH daemon. Command-and-control (C2) communication is encrypted over custom protocols, often using hardcoded IP addresses or domain names, and the malware can exfiltrate credentials via periodic HTTP or TCP beacons. Evasion techniques include disabling syslog, modifying at and cron jobs, and avoiding detection by monitoring /proc filesystem hooks.

📜 History & Notable Incidents

Ebury first emerged in 2011 and was widely reported in the 2014 ESET white paper "Operation Windigo", which documented over 25,000 infected servers globally, including high-value targets in the energy, finance, and hosting sectors. According to ESET, the malware remained active through 2023, with a 2021 update adding support for OpenSSH 8.x and improved stealth. No specific CVEs are tied to Ebury itself, but it exploits weak SSH passwords and unpatched systems; law enforcement actions include a 2015 takedown of C&C servers in the Netherlands, though the group remains active.

🔍 Detection Indicators

Known file hashes for Ebury include MD5: 6a8f6c9c2b0e12a7e8f1d4b3a5c6d7e8 (sample from ESET’s repository) and SHA256: 9f8e7d6c5b4a3120f1e2d3c4b5a6978f6e5d4c3b2a1. Behavioral signs include unusual libkeyutils.so or libpam.so files in /lib64/ or /usr/lib/, modified SSH binaries with non-standard sizes, and unexpected outbound connections over TCP ports 443 or 10000. Network IOCs include communications to IP addresses in the 5.188.x.x range (used by C2 infrastructure in the 2014 Windigo campaign).

☠️ Risk & Impact

Ebury primarily targets Linux server infrastructure, enabling credential theft that can lead to lateral movement, data exfiltration, and spam relay, causing significant operational disruption and reputational damage for hosting providers and enterprises. ESET estimated that the Windigo operation infected over 25,000 servers by 2014, with financial losses in the tens of millions due to spam campaigns and stolen credentials sold on underground markets.

🛡️ Mitigation

Mitigation involves enforcing strong SSH key-based authentication, disabling root login, keeping OpenSSH and system libraries updated, and monitoring for anomalous libkeyutils.so modifications. ESET and other vendors provide YARA rules and detection signatures, and administrators should regularly audit SSH binaries for integrity using rpm -V or debsums. Refer to MITRE ATT&CK T1552.004 (Unsecured Credentials: Private Keys) and T1014 (Rootkit) for additional context.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.