Linux/Ebury is a Linux and Unix server-side OpenSSH backdoor and credential-stealing malware family that served as the core component of Operation Windigo, a large-scale criminal campaign active since at least 2011. It was used to maintain covert root-level access to compromised servers, steal SSH credentials and key material, and support the broader monetization of infected infrastructure through spam operations, malicious web traffic redirection, and downstream malware delivery.
Linux/Ebury has appeared both as patched OpenSSH binaries and, more notably, as a trojanized shared library variant based on libkeyutils that is loaded into OpenSSH-related processes at runtime. The malware hooks authentication, logging, and network-related functions inside components such as ssh, sshd, ssh-agent, and ssh-add, allowing it to intercept successful and failed login passwords, passwords used from the infected host, private-key passphrases, unencrypted private keys, and keys added through SSH tooling. It also suppresses or alters logging to conceal unauthorized access and malware activity.
The backdoor supports covert operator access through specially crafted SSH protocol version strings. Once the embedded backdoor credential is validated, it can bypass normal authentication controls and enable otherwise disabled SSH authentication settings, including root login and password-based access. Linux/Ebury also supports operator commands for retrieving stored credentials and key material, reporting version or exfiltration configuration, and binding tunnel sockets to specific interfaces.
Credential theft is central to Linux/Ebury’s role. Stolen data has been exfiltrated through crafted DNS requests over UDP port 53, a technique likely intended to blend with ordinary network traffic and evade simplistic filtering. The malware also includes anti-monitoring behavior, including suppressing exfiltration when a network interface is in promiscuous mode. Later variants favored runtime patching and shared-library hooking over direct modification of OpenSSH binaries, improving stealth and resilience.
Linux/Ebury primarily targeted Linux servers, but infections were also documented on FreeBSD hosts, reflecting its focus on Unix-like systems running OpenSSH. The operators were assessed to rely mainly on stolen administrator credentials rather than exploitation of a new OpenSSH vulnerability, enabling lateral expansion across internet-facing infrastructure. Victims included hosting providers and prominent organizations, and the compromised servers were used as attacker-controlled infrastructure within the wider Windigo ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Linux/Ebury – an OpenSSH backdoor used to keep control of the servers and steal credentials
The second rule matches SSH credentials leaking out of the network. Any internal host sending DNS exfiltration packets will trigger the alert.
This server is the entry-point of a chain of reverse proxy servers terminating on an exploit serving machine.
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux/Ebury is a sophisticated OpenSSH backdoor and credential stealer targeting Linux and other POSIX systems. It is deployed as either a malicious library (libkeyutils.so) or as patched OpenSSH binaries (ssh, sshd, ssh-add). The malware hooks into OpenSSH processes to steal credentials (passwords, private keys, passphrases) and exfiltrates them via crafted DNS requests. It provides attackers with persistent access, disables logging during backdoor use, and allows remote command execution. It is manually deployed and does not self-propagate.
Server-side OpenSSH backdoor used to steal credentials from compromised servers; part of Operation Windigo infrastructure and used to maintain access to infected systems.
An OpenSSH backdoor that provides persistent root shell access on compromised Linux/Unix servers and steals SSH credentials, passphrases, and keys. It is described as the core component of Operation Windigo and is used for credential exfiltration, maintaining access, and supporting other malicious infrastructure.
Linux/Ebury is an OpenSSH backdoor central to the Windigo operation. It trojanizes SSH components, steals credentials and SSH keys/passphrases, uses shared memory for IPC, and supports data exfiltration and backdoor access on compromised servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.