Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
    • Layer 2
  • Tech
    • Blockchain
    • Security and Privacy
    • Mining
  • Web 3
    • Web3 News
    • DeFi
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
What's Hot

Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

16 June 2025

AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

16 June 2025

EU Crypto Rules Spark Backlash Over Fast-Track Licenses

16 June 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) LinkedIn
The Coin VibeThe Coin Vibe
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. Layer 2
    6. View All

    UK Gold Mining Company Bluebird To Convert Gold Revenues Into Bitcoin

    16 June 2025

    Bitcoin’s tug of war: Whale bets $200M as shorts stack to $1B – What next?

    16 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    $190,000 Bitcoin Within the ‘Realm of Possibility,’ According to Analyst Kevin Svenson – Here’s His Outlook

    15 June 2025

    Ethereum bears lose ground, but ETH bulls may not be safe just yet!

    16 June 2025

    Solana or Ethereum? – The fight for Q3 dominance starts now!

    15 June 2025

    $298 mln Ethereum liquidated across 80K traders: Yet BlackRock keeps buying

    15 June 2025

    Ethereum whales boost holdings by 1.49 mln – Can this trigger ETH’s breakout?

    14 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025

    Can it change the SHIB prize process?

    16 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    Solaxy Claim Guide and 2025’s Breakout Coin to watch: Pepeto

    15 June 2025

    Shiba Inu Burn Rate Spikes 3,484% as Kusama Teases AI Push

    14 June 2025

    Shiba Inu Enters AI-Gaming as SHIB Price Hits Critical Support

    13 June 2025

    The $CVB Launch Is Here — And It Starts With You

    13 June 2025

    Here’s What’s Pumping in June

    11 June 2025

    Soneium layer 2 launches gaming incubator to support projects and drive ecosystem adoption

    9 June 2025

    Immutable price drops even as Guild of Guardians NFT sales jump

    6 June 2025

    Cryptocurrencies to watch this week: Pi, Immutable, Zebec

    1 June 2025

    GOAT Network launches dashboard for first suite of on-chain Bitcoin yield products

    29 May 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. Mining
    4. View All

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    Upbit’s Banking Partner Joins Forces for South Korea Blockchain Advancement and Stablecoin Study

    16 June 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Quack AI Partners SoonChain to Redefine Governance in Web3 Gaming

    15 June 2025

    Environmental Websites Hit by DDoS Surge in COP28 Crossfire

    16 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025

    Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+

    15 June 2025

    Crypto Heists Surge in 2023, $16.93m Already Stolen in 2024

    15 June 2025

    American Bitcoin’s 25 EH/s Dream Rests on Chinese Hardware

    16 June 2025

    Russian Police Bust Truck-Based Crypto Mine Stealing Village Power

    15 June 2025

    France eyes Bitcoin mining as means to manage energy

    15 June 2025

    946 Exahash—Miners Push Bitcoin to New Computational Heights Despite Pay Drop

    14 June 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025
  • Web 3
    1. Web3 News
    2. DeFi
    3. View All

    How NFTs And Real-World Assets Will Reshape Global Markets

    16 June 2025

    XRP News: Vaultro Finance Presale on XRP ledger Skyrockets Past 50%, As Investors Race to Own $VLT Token

    15 June 2025

    Earn 5x GUN Tokens Monthly: A Complete Guide to Off the Grid Battle Pass

    15 June 2025

    United States Image Recognition Market Size & Industry Report 2033

    15 June 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    Bitcoin DeFi Is Taking Root on Sui—Here’s How It Works

    15 June 2025

    Sentora Highlights Capital Fragmentation and Infrastructure Gaps in Institutional DeFi

    15 June 2025

    MOCA Launches on Coinbase through Aerodrome DEX Integration, Expanding DeFi Access 

    15 June 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ripple and SEC Case Close with $125M Escrow Deal in Joint Court Filing

    16 June 2025

    Elizabeth Warren, Consumer Groups Slam Walmart and Amazon Stablecoin Plans

    15 June 2025

    New and Important Development in the Ripple vs. SEC Lawsuit – All Eyes on the Judge Now

    15 June 2025

    KuCoin EU Appoints Banking Veteran Christian Derler And Legal Expert Tamara Rubey

    10 June 2025

    GameStop Drives Strategic Diversification With Staggering 4,710 $BTC Buyout

    28 May 2025

    Bybit Receives Clearance From French Regulator, Eyes MiCA License For Compliance Boost

    22 May 2025

    Bitget Secures VASP License In Bulgaria, Strengthening EU Expansion

    22 May 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025
  • Analysis

    Trader Says One Layer-1 Altcoin ‘Destined’ for New All-Time High, Warns of Potential 50% Correction for WIF and POPCAT

    16 June 2025

    Crypto Strategist Warns of up to 80% Bitcoin Correction in Next Bear Market Fueled by Selling of Major BTC Adoption Group

    15 June 2025

    Bullish and Bearish Scenarios Explained

    15 June 2025

    Can Pi Network Price Hit $10?

    15 June 2025

    Billionaire Investor Ray Dalio Outlines Meme Stock Trading Strategy, Says Investors Are Not Paying Enough Attention to the ‘Most Important Thing’

    14 June 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    15 June 2025

    The Crypto Minimalist: Building Wealth by Doing Less

    15 June 2025

    The Crypto-Side Hustle Blueprint: How to Earn in Web3 Without Trading

    13 June 2025

    What is LIBRA? The Solana Meme Coin That Sparked a Political Scandal

    12 June 2025

    Binance Is Not Dumping SOL And ETH Through Wintermute

    23 May 2025

    US SEC Agency Drops Gemini & Tron ($TRX) Lawsuit

    23 May 2025

    Nischal Says Voting On The Wazirx Restructuring Scheme Will Start On 19 March

    22 May 2025

    Coinbase Secures Regulatory Approval To Resume Services In India

    22 May 2025

    Top 10 Alternative Chains Diversifying DeFi, Ethereum Maintains Dominance

    16 June 2025

    AltLayer Partners with T-Rex for Web3 Scaling for 3.5B Consumers

    16 June 2025

    EU Crypto Rules Spark Backlash Over Fast-Track Licenses

    16 June 2025

    Ethena: Can Mellow Finance’s $ 4.48 million bet Spark Ena’s recovery?

    16 June 2025
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
Subscribe
The Coin VibeThe Coin Vibe
Home»Security and Privacy»Ebury Botnet Operators Diversify with Financial and Crypto Theft
Security and Privacy

Ebury Botnet Operators Diversify with Financial and Crypto Theft

9 June 2025No Comments5 Mins Read
Share Facebook Twitter LinkedIn
Ebury Botnet Operators Diversify with Financial and Crypto Theft
Share
Facebook Twitter LinkedIn

Ebury, one of the most advanced server-side malware campaigns, has been active for 15 years, but its use by threat factors is still growing, according to cyber security company ESET.

From a new report published on 14 May by ESET research showed that operators from the Ebury Malware and Botnet in 2023 were more active than ever.

Over the years, Ebury has been used as a back door to jeopardize nearly 400,000 Linux, FreeBSD and OpenBSD servers. More than 100,000 were still affected from the end of 2023.

The Ebury Group has long known for spam, web traffic and stealing, the Ebury Group recently added credit compromise and cryptocurrency theft in its techniques, tactics and procedures (TTPS).

What is the Ebury -Botnet?

Ebury is a malicious group that has been active since 2009. It has developed an OpenSSH key door and a reference steamer that is used to implement multiple malware strains at the same time by trusting a BOT network (Botnet).

The primary goals of the group are hosting providers.

The Ebury-Botnet is used to jeopardize Linux, FreeBSD and OpenBSD servers to implement web traffic control modules, proxy traffic for spam or to perform opponents-in-the-middle attacks (AITM).

In 2014, ESET published a white paper on Operation Windigo, a malignant campaign with several malware families that work in the core in combination with the Ebury Malware family.

After the release of the Windigo paper, the Russian National Senakh, one of the Ebury operators, was arrested in 2015 on the border with Finland-Russia and later extradited to the US.

See also  Pakistan Launches Digital Asset Authority to Regulate Crypto, Targeting $25B Market

In 2017 he was sentenced to 46 months in prison in the US for his role in running the Ebury botnet. ESET assisted the FBI in the operation and testified during the test.

At the end of 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Dutch National Police, contacted ESET after they found Ebury on the server of a victim of Cryptocurrency theft.

“Those suspicions were found to be well substantiated and with the help of NHTCU, ESET Research has had considerable visibility in the activities of the Ebury Threat Actors,” the new ESET report indicated.

Marc-Etienne M. Léveillé, the ESET researcher who has investigated Ebury for more than ten years, noted: “We have documented fallen […] Where the Ebury actors could put thousand servers at the same time. There is no geographical border on Ebury; Servers have been compromised with Ebury in almost all countries in the world. When a hosting provider was affected, this led to a large number of compromised servers in the same data centers.

“At the same time, there are no more verticals focused than others. Victims are universities, small and large companies, internet providers, cryptocurrency traders, exit nodes, shared hosting providers and dedicated server providers, to name just a few.”

Ebury’s new favorite goals: Bitcoin and Ethereum nodes

Despite the arrest, the Ebury Group continued to conduct more malicious campaigns, at least until the end of 2023.

The ESET report describes new methods used to distribute Ebury to new servers that appeared after 2021.

See also  Donald Trump Jr. Says Family Got Into Crypto After Being Debanked, Realizing Financial System Was ‘Pyramid Scheme’

From his access to the infrastructure of his goal, usually a hosting provider, the Ebury Group can use different types of attacks.

In one of the most recent, the group uses an AITM attack to intercept SSH traffic from attractive purposes in data centers and forward it to a server used to record login data.

The malicious actors use existing Ebury-compromised servers in the same network segment as their target to perform address resolution Protocol (ARP) Spoofing. Among the goals are Bitcoin and Ethereum nodes. Ebury automatically steals cryptocurrency portfolios hosted on the intended server as soon as the victim type the password to log in.

ESET has noted that this method was used to focus more than 200 goals on more than 75 networks in 34 countries between February 2022 and May 2023.

This example not only illustrates one of Ebury’s latest attack techniques, but also one of the newest vectors of the group’s income: theft of cryptocurrency.

Moreover, the Ebury Malware family itself has also been updated.

The new update of the large version, 1.8, to be seen for the first time in the end of 2023, included new Obfuscation techniques, a new domain teneration -algorithm (DGA) and improvements in the by Ebury Userland Rootkit to hide themselves from system administrators. When active, the process, the file, the socket and even the assigned memory are hidden.

2023, a record year for Ebury

These shifts in the infection and monetization methods of the Ebury Group seem to bear fruit, because the activity of the group increased considerably in 2023 compared to 2021.

See also  New ‘Chihuahua Stealer' Targets Browser Data and Crypto Wallets

“The perpetrators keep track of the systems they have compromised and we used that data to draw a timeline of the number of new servers that have been added to the Botnet every month,” the ESET researchers wrote.

August 2023 saw record -breaking activity of the group, with that month more than 6,000 compromised servers.

Combined, around 400,000 servers have been compromised since 2009 by Ebury and more than 100,000 were still affected from the end of 2023.

Botnet Crypto Diversify Ebury Financial Operators Theft
Follow on X (Twitter)
Share. Facebook Twitter LinkedIn
Previous ArticleCryplex AI and Accumulate (L1 Blockchain) Form Partnership to Boost Decentralized AI and Identity
Next Article Major Cryptocurrencies Struggle as Hang Seng Cheers U.S.-China Trade Talks; U.S. Inflation Eyed as China Deflation Worsens

Related Posts

Legal and Regulatory

EU Crypto Rules Spark Backlash Over Fast-Track Licenses

16 June 2025
Security and Privacy

Environmental Websites Hit by DDoS Surge in COP28 Crossfire

16 June 2025
Altcoins

Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

15 June 2025
Add A Comment
Leave A Reply Cancel Reply

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Posts
Mining

Nebraska to Make Bitcoin Mining More Difficult With a New Bill

21 May 2025
Legal and Regulatory

$345,000,000,000 Asset Manager Urges US To Get House in Order, Warns Debt Now Increasing Faster Than Economic Growth

28 May 2025
Top Posts

Can Solana Break the $180 Resistance? Here’s What SOL Price Will Be Worth in 2025!

24 May 2025128 Views

Trump Family Backed American Bitcoin To Go Public via Merger With Gryphon Digital

20 May 202516 Views

Wazirx’s Nischal Shetty Reports $478.5m Net Liquid Assets As Voting Starts

20 May 202512 Views

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest
Top Insights

3 undervalued cryptos set to Skyrocket: Cardano, Remittix and Dogecoin

23 May 2025

Dogecoin Flits

28 May 2025

AVAX Surges 6% After Musk/Trump Dispute Sell-Off

6 June 2025
Get Informed

Subscribe to Updates

Spice Up Your Crypto Knowledge – Get the Latest News & Insights Straight to Your Inbox!

Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 thecoinvibe.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.