ESET reported that the Ebury Linux malware operation has remained active for more than a decade, compromising roughly 400,000 servers since 2009 and leaving more than 100,000 still infected as of late 2023. Identified as an OpenSSH backdoor and credential stealer, Ebury has continued to evolve from its earlier role in the Operation Windigo crimeware ecosystem, where it supported spam, web traffic redirection, exploit-kit delivery, and broader server-side abuse while allowing legitimate services to keep running and delaying detection.
Recent Ebury versions added stronger obfuscation, a new domain generation algorithm (DGA), and improved rootkit features, while operators expanded propagation through compromised hosting providers and adversary-in-the-middle SSH interception via ARP spoofing inside data centers. The group also broadened monetization beyond spam and redirects to include theft of credit card and financial data from HTTP POST traffic and cryptocurrency wallet theft targeting Bitcoin and Ethereum nodes, showing that a long-running Linux server botnet first exposed during Windigo has adapted into a durable platform for credential theft and financial crime.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
On 2024-05-14, ESET reported that Ebury had compromised about 400,000 Linux servers since 2009 and had expanded beyond spam and traffic redirection into credit card and cryptocurrency theft. The report also detailed propagation through compromised hosting providers and theft from Bitcoin and Ethereum nodes.
As of late 2023, ESET reported that more than 100,000 servers were still compromised by Ebury. This showed the botnet remained active and extensive years after Operation Windigo.
A major Ebury update, version 1.8, was first seen in late 2023. ESET said it introduced stronger obfuscation, a new domain generation algorithm, and improved rootkit capabilities.
In 2023, internet telemetry indicated that more than 200 servers were targeted by Ebury operators using adversary-in-the-middle SSH interception attacks inside data centers. The attackers used compromised servers in the same network segment to perform ARP spoofing and capture credentials.
In 2021, the Dutch National High Tech Crime Unit contacted ESET after finding Ebury on the server of a cryptocurrency theft victim. The two organizations then worked together to gain visibility into the group's recent activity and malware.
On 2014-10-15, ESET said the Windigo gang's malicious activity had not decreased since its March 2014 report and that Ebury had been updated to evade detection. The update also described technical changes in newer Ebury versions and noted CERT-Bund had refreshed its IOC page based on ESET's findings.
Within a month of ESET's March 2014 publication, ESET observed a new Ebury version that evaded the indicators of compromise it had published. The update showed the operators reacted quickly to public research.
ESET first saw Ebury version 1.4.1 in April 2014, showing the malware was continuing to evolve after the March 2014 Windigo report. This marked an early post-disclosure update in the malware's development.
In March 2014, ESET published its Operation Windigo report describing a profit-driven malware ecosystem involving more than 10,000 infected servers worldwide, with Ebury as an OpenSSH backdoor component. The report tied together credential theft, web traffic redirection, exploit-kit delivery, and spam monetization.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcewelivesecurity.com
Open sourceweb-assets.esetstatic.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.