{"id":3626,"date":"2024-05-17T11:00:00","date_gmt":"2024-05-17T16:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/400k-linux-servers-recruited-by-resurrected-ebury-botnet"},"modified":"2024-05-17T11:00:00","modified_gmt":"2024-05-17T16:00:00","slug":"400k-linux-servers-recruited-by-resurrected-ebury-botnet","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/17\/400k-linux-servers-recruited-by-resurrected-ebury-botnet\/","title":{"rendered":"400K Linux Servers Recruited by Resurrected Ebury Botnet"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt15a7548ce65478b0\/64f1733bec1d250344a6a9d9\/cryptocurrency_Skorzewiak-AlamyStockPhoto.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Linux-based botnet is alive and well, powering cryptocurrency theft and financial scams years after the imprisonment of one the key perpetrators behind it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Ebury botnet \u2013 which was first discovered 15 years ago \u2013 has backdoored nearly 400,000 Linux, FreeBSD, and OpenBSD servers. More than 100,000 servers were still compromised as of late 2023, according to new research from cybersecurity vendor ESET.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Victims include universities, small and large enterprises, Internet service providers, cryptocurrency traders, Tor exit nodes, and many hosting providers worldwide.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Anatomy of a Threat\">Anatomy of a Threat<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ebury is an OpenSSH backdoor that&#8217;s used to steal credentials like SSH keys and passwords. It creates a backdoor on the infected server that facilitates the deployment of secondary malware modules such as Cdorked, an HTTP backdoor used to redirect Web traffic and modify DNS settings, and Calfbot, a Perl script used to send spam emails.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over the years, Ebury has served as a platform for spam distribution, Web traffic redirections, and credential-stealing, among other scams. Most recently, the gang running the botnet has pivoted to credit card and cryptocurrency theft, researchers found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attackers use adversary-in-the-middle tactics to intercept the SSH traffic of interesting targets \u2013 including Bitcoin and Ethereum nodes &#8211; within data centers, and then redirecting traffic to a server under their control. Once a would-be victim types their password into a cryptocurrency wallet hosted on the compromised server, Ebury automatically steals those wallets, according to ESET, which this week released <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain\/\" rel=\"noopener\">updated research<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/white-papers\/ebury-is-alive-but-unseen.pdf\" rel=\"noopener\">white paper on the Ebury botnet<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They also appear to be making attempts to muscle out potential credit card theft competitors. Case in point: Ebury malware attempts to detect and remove the BigBadWolf banking Trojan from compromised systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ebury&#8217;s operators employ zero-day vulnerabilities in the server administrator software to hack servers at scale and extract credentials from the victim servers, the researchers found. The attackers also use known passwords and keys to hack into related systems, which allow them to surreptitiously install Ebury on multiple servers rented from any compromised hosting providers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At one hosting provider, total of 70,000 servers were compromised by Ebury in 2023, the researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Whenever a hosting provider was compromised, it led to a vast number of compromised servers in the same data centers,&#8221; wrote ESET researcher Marc-Etienne M. L\u00e9veill\u00e9, who has been investigating Ebury for more than a decade.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In perhaps one of Ebury&#8217;s most infamous campaigns, from 2009 to 20011 it successfully hacked Kernel.org, which hosts the source code of the Linux kernel. Half of its Kernel.org&#8217;s developer SSH passwords were stolen during that period.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cops and Robbers\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Cops and Robbers<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2014, ESET revealed that it had teamed up with Dutch police in an investigation of servers in the Netherlands suspected of being compromised with Ebury malware. Then in 2015, one of the Ebury perpetrators, Russian citizen Maxim Senak, was arrested at the Finland-Russia border and extradited to the US. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/opa\/pr\/russian-citizen-sentenced-46-months-prison-involvement-global-botnet-conspiracy\" rel=\"noopener\">He eventually pled guilty to fraud<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and computer hacking charges in 2017 and was sentenced to 46 months in prison. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Since then, Ebury&#8217;s remaining masterminds have kept a low profile. They don&#8217;t advertise their activities and &#8220;we&#8217;ve never seen them attempting to sell access&#8221; to compromised systems on Dark Net forums, ESET&#8217;s L\u00e9veill\u00e9 wrote in his post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Dutch National High Tech Crime Unit (NHTCU) in 2021 contacted ESET after finding Ebury on the server of a victim of cryptocurrency theft. That law enforcement investigation into Ebury remains ongoing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Keeping Linux Safe from Ebury\">Keeping Linux Safe from Ebury<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ebury malware operators regularly add new features. The latest version 1.8.2, spotted earlier this year, bundles new obfuscation techniques, a new domain-generation algorithm, and a stealthier rootkit functionality.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ESET this week released a set of detection and remediation tools to help system administrators determine whether their systems are compromised by Ebury.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Clean-up operations are non-trivial for an Ebury infection, ESET warns. Robert Lipovsky, principal threat intelligence researcher at ESET, told Dark Reading that even if system admins sanitize their infected servers, the cybercriminals behind Ebury might be able to reinstall the malware if compromised credentials get reused.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While there are tools available for adding multi-factor authentication to SSH servers, deployment is not simple, so systems admins often skip that extra level of security. &#8220;The continuing problems posed by Ebury illustrate the lack of visibility on Linux-based server-side threats,&#8221; ESET&#8217;s L\u00e9veill\u00e9 told Dark Reading.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/400k-linux-servers-recruited-by-resurrected-ebury-botnet\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Linux-based botnet is alive and well, powering cryptocurrency theft<\/p>\n","protected":false},"author":12,"featured_media":3627,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3626","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=1450%2C850&ssl=1",1450,850,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=640%2C375&ssl=1",640,375,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=640%2C375&ssl=1",640,375,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=1450%2C850&ssl=1",1450,850,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=1450%2C850&ssl=1",1450,850,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=1024%2C600&ssl=1",1024,600,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/400k-linux-servers-recruited-by-resurrected-ebury-botnet.jpg?fit=1450%2C850&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3626"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3626\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3627"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}