Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
    • Layer 2
  • Tech
    • Blockchain
    • Security and Privacy
    • Mining
  • Web 3
    • Web3 News
    • DeFi
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
What's Hot

Michael Saylor Joins Pakistan’s Crypto Mission

16 June 2025

Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

16 June 2025

Virtual Real Estate and Metaverse Market Forecast (2025-2030)

16 June 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) LinkedIn
The Coin VibeThe Coin Vibe
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. Layer 2
    6. View All

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Trader Predicts Rallies to New All-Time High for Bitcoin Amid Struggle To Clear $110,000 – But There’s a Big Catch

    16 June 2025

    Risk of Escalating Israel-Iran Conflict Keeps Bitcoin Around 105K Says QCP

    16 June 2025

    UK Gold Mining Company Bluebird To Convert Gold Revenues Into Bitcoin

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Ethereum sees $153mln inflow – But THIS kept ETH price frozen

    16 June 2025

    Ethereum bears lose ground, but ETH bulls may not be safe just yet!

    16 June 2025

    Solana or Ethereum? – The fight for Q3 dominance starts now!

    15 June 2025

    A prediction of the price – a deeper retracement can be on the cards because …

    16 June 2025

    Founder of Cardano confirms XRP Defi package and RLUSD interviews

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025

    Can it change the SHIB prize process?

    16 June 2025

    Shiba Inu Burn Rate Spikes 3,484% as Kusama Teases AI Push

    14 June 2025

    Shiba Inu Enters AI-Gaming as SHIB Price Hits Critical Support

    13 June 2025

    The $CVB Launch Is Here — And It Starts With You

    13 June 2025

    Here’s What’s Pumping in June

    11 June 2025

    Soneium layer 2 launches gaming incubator to support projects and drive ecosystem adoption

    9 June 2025

    Immutable price drops even as Guild of Guardians NFT sales jump

    6 June 2025

    Cryptocurrencies to watch this week: Pi, Immutable, Zebec

    1 June 2025

    GOAT Network launches dashboard for first suite of on-chain Bitcoin yield products

    29 May 2025

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. Mining
    4. View All

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    Upbit’s Banking Partner Joins Forces for South Korea Blockchain Advancement and Stablecoin Study

    16 June 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    North Korean Hackers Stole $600m in Crypto in 2023

    16 June 2025

    Environmental Websites Hit by DDoS Surge in COP28 Crossfire

    16 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025

    Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+

    15 June 2025

    American Bitcoin’s 25 EH/s Dream Rests on Chinese Hardware

    16 June 2025

    Russian Police Bust Truck-Based Crypto Mine Stealing Village Power

    15 June 2025

    France eyes Bitcoin mining as means to manage energy

    15 June 2025

    946 Exahash—Miners Push Bitcoin to New Computational Heights Despite Pay Drop

    14 June 2025

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025
  • Web 3
    1. Web3 News
    2. DeFi
    3. View All

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Share issue to personnel – 14 June 2025

    16 June 2025

    How NFTs And Real-World Assets Will Reshape Global Markets

    16 June 2025

    XRP News: Vaultro Finance Presale on XRP ledger Skyrockets Past 50%, As Investors Race to Own $VLT Token

    15 June 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    Bitcoin DeFi Is Taking Root on Sui—Here’s How It Works

    15 June 2025

    Sentora Highlights Capital Fragmentation and Infrastructure Gaps in Institutional DeFi

    15 June 2025

    MOCA Launches on Coinbase through Aerodrome DEX Integration, Expanding DeFi Access 

    15 June 2025

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    David Sacks Optimistic On Clarity Act, More Regulatory Clarity

    16 June 2025

    Gemini and Coinbase set to secure EU licenses

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ripple and SEC Case Close with $125M Escrow Deal in Joint Court Filing

    16 June 2025

    KuCoin EU Appoints Banking Veteran Christian Derler And Legal Expert Tamara Rubey

    10 June 2025

    GameStop Drives Strategic Diversification With Staggering 4,710 $BTC Buyout

    28 May 2025

    Bybit Receives Clearance From French Regulator, Eyes MiCA License For Compliance Boost

    22 May 2025

    Bitget Secures VASP License In Bulgaria, Strengthening EU Expansion

    22 May 2025

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025
  • Analysis

    Is $190 the Next Milestone?

    16 June 2025

    Can Pi Network Price Hit $100?

    16 June 2025

    Trader Says One Layer-1 Altcoin ‘Destined’ for New All-Time High, Warns of Potential 50% Correction for WIF and POPCAT

    16 June 2025

    Crypto Strategist Warns of up to 80% Bitcoin Correction in Next Bear Market Fueled by Selling of Major BTC Adoption Group

    15 June 2025

    Bullish and Bearish Scenarios Explained

    15 June 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    15 June 2025

    The Crypto Minimalist: Building Wealth by Doing Less

    15 June 2025

    The Crypto-Side Hustle Blueprint: How to Earn in Web3 Without Trading

    13 June 2025

    What is LIBRA? The Solana Meme Coin That Sparked a Political Scandal

    12 June 2025

    Binance Is Not Dumping SOL And ETH Through Wintermute

    23 May 2025

    US SEC Agency Drops Gemini & Tron ($TRX) Lawsuit

    23 May 2025

    Nischal Says Voting On The Wazirx Restructuring Scheme Will Start On 19 March

    22 May 2025

    Coinbase Secures Regulatory Approval To Resume Services In India

    22 May 2025

    Michael Saylor Joins Pakistan’s Crypto Mission

    16 June 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    16 June 2025

    Virtual Real Estate and Metaverse Market Forecast (2025-2030)

    16 June 2025

    Mira and GoPlus Team Up to Verify AI Security Answers Across Web3

    16 June 2025
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
Subscribe
The Coin VibeThe Coin Vibe
Home»Security and Privacy»Ebury Botnet Operators Diversify with Financial and Crypto Theft
Security and Privacy

Ebury Botnet Operators Diversify with Financial and Crypto Theft

9 June 2025No Comments5 Mins Read
Share Facebook Twitter LinkedIn
Ebury Botnet Operators Diversify with Financial and Crypto Theft
Share
Facebook Twitter LinkedIn

Ebury, one of the most advanced server-side malware campaigns, has been active for 15 years, but its use by threat factors is still growing, according to cyber security company ESET.

From a new report published on 14 May by ESET research showed that operators from the Ebury Malware and Botnet in 2023 were more active than ever.

Over the years, Ebury has been used as a back door to jeopardize nearly 400,000 Linux, FreeBSD and OpenBSD servers. More than 100,000 were still affected from the end of 2023.

The Ebury Group has long known for spam, web traffic and stealing, the Ebury Group recently added credit compromise and cryptocurrency theft in its techniques, tactics and procedures (TTPS).

What is the Ebury -Botnet?

Ebury is a malicious group that has been active since 2009. It has developed an OpenSSH key door and a reference steamer that is used to implement multiple malware strains at the same time by trusting a BOT network (Botnet).

The primary goals of the group are hosting providers.

The Ebury-Botnet is used to jeopardize Linux, FreeBSD and OpenBSD servers to implement web traffic control modules, proxy traffic for spam or to perform opponents-in-the-middle attacks (AITM).

In 2014, ESET published a white paper on Operation Windigo, a malignant campaign with several malware families that work in the core in combination with the Ebury Malware family.

After the release of the Windigo paper, the Russian National Senakh, one of the Ebury operators, was arrested in 2015 on the border with Finland-Russia and later extradited to the US.

See also  In 2025, crypto firms go public in record numbers

In 2017 he was sentenced to 46 months in prison in the US for his role in running the Ebury botnet. ESET assisted the FBI in the operation and testified during the test.

At the end of 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Dutch National Police, contacted ESET after they found Ebury on the server of a victim of Cryptocurrency theft.

“Those suspicions were found to be well substantiated and with the help of NHTCU, ESET Research has had considerable visibility in the activities of the Ebury Threat Actors,” the new ESET report indicated.

Marc-Etienne M. Léveillé, the ESET researcher who has investigated Ebury for more than ten years, noted: “We have documented fallen […] Where the Ebury actors could put thousand servers at the same time. There is no geographical border on Ebury; Servers have been compromised with Ebury in almost all countries in the world. When a hosting provider was affected, this led to a large number of compromised servers in the same data centers.

“At the same time, there are no more verticals focused than others. Victims are universities, small and large companies, internet providers, cryptocurrency traders, exit nodes, shared hosting providers and dedicated server providers, to name just a few.”

Ebury’s new favorite goals: Bitcoin and Ethereum nodes

Despite the arrest, the Ebury Group continued to conduct more malicious campaigns, at least until the end of 2023.

The ESET report describes new methods used to distribute Ebury to new servers that appeared after 2021.

See also  German Police Shutter Country’s Largest Dark Web Market

From his access to the infrastructure of his goal, usually a hosting provider, the Ebury Group can use different types of attacks.

In one of the most recent, the group uses an AITM attack to intercept SSH traffic from attractive purposes in data centers and forward it to a server used to record login data.

The malicious actors use existing Ebury-compromised servers in the same network segment as their target to perform address resolution Protocol (ARP) Spoofing. Among the goals are Bitcoin and Ethereum nodes. Ebury automatically steals cryptocurrency portfolios hosted on the intended server as soon as the victim type the password to log in.

ESET has noted that this method was used to focus more than 200 goals on more than 75 networks in 34 countries between February 2022 and May 2023.

This example not only illustrates one of Ebury’s latest attack techniques, but also one of the newest vectors of the group’s income: theft of cryptocurrency.

Moreover, the Ebury Malware family itself has also been updated.

The new update of the large version, 1.8, to be seen for the first time in the end of 2023, included new Obfuscation techniques, a new domain teneration -algorithm (DGA) and improvements in the by Ebury Userland Rootkit to hide themselves from system administrators. When active, the process, the file, the socket and even the assigned memory are hidden.

2023, a record year for Ebury

These shifts in the infection and monetization methods of the Ebury Group seem to bear fruit, because the activity of the group increased considerably in 2023 compared to 2021.

See also  Money Laundering Dominates UK Fraud Cases

“The perpetrators keep track of the systems they have compromised and we used that data to draw a timeline of the number of new servers that have been added to the Botnet every month,” the ESET researchers wrote.

August 2023 saw record -breaking activity of the group, with that month more than 6,000 compromised servers.

Combined, around 400,000 servers have been compromised since 2009 by Ebury and more than 100,000 were still affected from the end of 2023.

Botnet Crypto Diversify Ebury Financial Operators Theft
Follow on X (Twitter)
Share. Facebook Twitter LinkedIn
Previous ArticleCryplex AI and Accumulate (L1 Blockchain) Form Partnership to Boost Decentralized AI and Identity
Next Article Major Cryptocurrencies Struggle as Hang Seng Cheers U.S.-China Trade Talks; U.S. Inflation Eyed as China Deflation Worsens

Related Posts

Bitcoin

Michael Saylor Joins Pakistan’s Crypto Mission

16 June 2025
Security and Privacy

North Korean Hackers Stole $600m in Crypto in 2023

16 June 2025
Legal and Regulatory

EU Crypto Rules Spark Backlash Over Fast-Track Licenses

16 June 2025
Add A Comment
Leave A Reply Cancel Reply

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Posts
Web3

SoarFun Launches New Era of Web3 Interaction with Gatrifi: A Gamified, Transparent Platform for On-Chain Engagement

12 June 2025
Bitcoin

Gemini Files Draft With The SEC For Proposed IPO

8 June 2025
Top Posts

Can Solana Break the $180 Resistance? Here’s What SOL Price Will Be Worth in 2025!

24 May 2025128 Views

Trump Family Backed American Bitcoin To Go Public via Merger With Gryphon Digital

20 May 202516 Views

Wazirx’s Nischal Shetty Reports $478.5m Net Liquid Assets As Voting Starts

20 May 202512 Views

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest
Top Insights

Ozean and Brickken Partner to Accelerate DeFi Access to Real-World Assets

22 May 2025

Tilted Joins Quizon to Gamify Web3 Learning

2 June 2025

Everything you need to know about the $3.8B in Bitcoin, Ethereum Options expiry

7 June 2025
Get Informed

Subscribe to Updates

Spice Up Your Crypto Knowledge – Get the Latest News & Insights Straight to Your Inbox!

Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 thecoinvibe.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.