Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

June 5, 2026

As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

June 5, 2026

XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

June 5, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    How Low Will Bitcoin Price Go After 13% Crash?

    June 4, 2026

    Legendary Trader Peter Brandt Details Downside Price Target for Bitcoin After BTC Breaks From ‘Reliable’ Pattern

    June 4, 2026

    Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

    June 4, 2026

    Tom Lee’s BitMine Seeks $300 Million Raise to Buy More Ethereum

    June 4, 2026

    Ethereum Crashes 60% As Analysts Dump ETH And Rotate Into These Altcoins

    June 4, 2026

    Ethereum Weakness May Be Final Phase Before Next Market Expansion

    June 4, 2026

    Ethereum’s Multi-Year Support Test Could Shape Its Next Big Move

    June 4, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Bitcoin’s $60K Range Seen As Potential Long-Term Accumulation Zone, Analyst Says

    June 4, 2026

    JPMorgan Chase CEO Speaks Out Against Clarity Act, Says Banks Will Fight Bill in Upcoming Markup

    June 4, 2026

    Bitcoin Traders Turn Most Fearful In 2 Months Following Crash

    June 4, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    Big tech is ‘terrified’ of AI agents wiping out ad revenue, says Billions Network CEO

    June 5, 2026

    Top Crypto Events to Watch This Week Across Europe and Beyond

    June 4, 2026

    Tezos Unveils TzEL, an Experimental Post‑Quantum Privacy Rollup

    June 4, 2026

    Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

    June 3, 2026

    Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

    May 29, 2026

    Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

    May 29, 2026

    New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

    May 28, 2026

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026
  • Web 3
    1. Gaming
    2. View All

    Pi Network Expands Gaming Ecosystem as CiDi Games Launches Developer Center

    June 3, 2026

    GMATRIXS Taps GamePad to Boost Web3 Gaming and DeFi Infrastructure

    June 3, 2026

    Code as Constitution: How Crypto Governance Is Moving Into the Real World

    June 2, 2026

    Why Toncoin Is Rising as Telegram Pushes Past Tap-to-Earn

    June 2, 2026

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026

    Banks’ survey says people don’t want to rock the boat if stablecoin yield risks lending

    June 4, 2026

    SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

    June 4, 2026

    Blockchain Association urges Senate to pass Clarity Act with letter from 160 former security officials

    June 4, 2026

    Bank of England stablecoin caps may choke the UK’s pound-token market before launch

    June 3, 2026

    Cardano just canceled is 2026 Summit

    June 2, 2026

    Trader turns $2,480 into $12 million after holding Binance memecoin for 8 months

    June 1, 2026

    Crypto walked so banks could run

    May 30, 2026

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026
  • Analysis

    Bitcoin’s selloff is creating the short-heavy setup that could reverse it fast

    June 4, 2026

    Wedbush’s Dan Ives Sees 30% Upside for ‘Mispriced’ Mag 7 Stock, Says AI Could Hit Monetization Phase in Coming Months

    June 4, 2026

    Here’s What Traders Are Watching

    June 4, 2026

    Zcash was rumored to have stopped working

    June 4, 2026

    Here’s Why BTC Could Fall to $54K

    June 4, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Mt. Gox-linked wallets moved 10,422 BTC, worth roughly $739 million as BTC price slides

    June 4, 2026

    XRP is sitting on a volatility trap as liquidity dries up and leverage builds

    May 27, 2026

    Kraken moves Bitcoin to Chainlink as bridge fears spread across DeFi

    May 16, 2026

    ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

    June 5, 2026

    As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

    June 5, 2026

    XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

    June 5, 2026

    Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

    June 5, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Ebury Botnet Operators Diversify with Financial and Crypto Theft
Ebury Botnet Operators Diversify with Financial and Crypto Theft
Security and Privacy

Ebury Botnet Operators Diversify with Financial and Crypto Theft

September 22, 2025No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Ebury, one of the most advanced server-side malware campaigns, has been active for 15 years but its use by threat actors is still growing, according to cybersecurity firm ESET.

A new report published on May 14 by ESET Research showed that operators of the Ebury malware and botnet were more active than ever in 2023.

Over the years, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD and OpenBSD servers. More than 100,000 were still compromised as of late 2023.

Long known to deploy spam, web traffic redirections and credential stealing, the Ebury group recently added credit card compromise and cryptocurrency theft in its techniques, tactics and procedures (TTPs).

What is the Ebury Botnet?

Ebury is a malicious group that has been active since at least 2009. It has developed an OpenSSH backdoor and a credential stealer used to deploy multiple malware strains simultaneously by relying on a bot network (botnet).

The group’s primary targets are hosting providers.

The Ebury botnet is used to compromise Linux, FreeBSD and OpenBSD servers in order to deploy web traffic redirection modules, proxy traffic for spam or perform adversary-in-the-middle attacks (AitM).

In 2014, ESET published a white paper about Operation Windigo, a malicious campaign using multiple malware families working in combination with the Ebury malware family at its core.

Following the release of the Windigo paper, Russian national Maxim Senakh, one of the Ebury operators, was arrested at the Finland-Russia border in 2015, and later extradited to the US.

In 2017, he was sentenced to 46 months in prison in the US for his role in running the Ebury botnet. ESET assisted the FBI in the operation and testified during the trial.

See also  New Cloud Attack Targets Crypto CDN Meson Ahead of Launch

In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Netherlands national police, contacted ESET after they had found Ebury on the server of a victim of cryptocurrency theft.

“Those suspicions turned out to be well-founded and with NHTCU’s assistance, ESET Research has gained considerable visibility into operations run by the Ebury threat actors,” the new ESET report indicated.

Marc-Etienne M. Léveillé, the ESET researcher who investigated Ebury for more than a decade, commented: “We have documented cases […] where the Ebury actors were able to compromise thousands of servers at once. There is no geographical boundary to Ebury; there are servers compromised with Ebury in almost all countries in the world. Whenever a hosting provider was compromised, it led to a vast number of compromised servers in the same data centers.

“At the same time, no verticals appear more targeted than others. Victims include universities, small and large enterprises, internet service providers, cryptocurrency traders, Tor exit nodes, shared hosting providers and dedicated server providers, to name a few.”

Ebury’s New Favorite Targets: Bitcoin and Ethereum Nodes

Despite the arrest, the Ebury group has continued running malicious campaigns, at least until late 2023.

The ESET report describes new methods used to propagate Ebury to new servers that appeared after 2021.

From its access to its target’s infrastructure, usually a hosting provider, the Ebury group can deploy several types of attacks.

In one of the most recent ones, the group uses an AitM attack to intercept SSH traffic of attractive targets inside data centers and redirect it to a server used to capture credentials.

See also  Crypto Exchange Bitrue Loses $4.5m in Cyber Raid

The malicious actors leverage existing Ebury-compromised servers in the same network segment as their target to perform Address Resolution Protocol (ARP) spoofing. Among the targets are Bitcoin and Ethereum nodes. Ebury automatically steals cryptocurrency wallets hosted on the targeted server once the victim types the password to log into it.

ESET has observed that this method was used to target over 200 targets across over 75 networks in 34 countries between February 2022 and May 2023. 

This example not only illustrates one of Ebury’s latest attack techniques, but also one of the group’s newest vectors of monetization: cryptocurrency theft.

Additionally, the Ebury malware family itself has also been updated.

The new major version update, 1.8, first seen in late 2023, included new obfuscation techniques, a new domain generation algorithm (DGA) and improvements in the userland rootkit used by Ebury to hide itself from system administrators. When active, the process, the file, the socket and even the mapped memory are hidden.

2023, a Record-Breaking Year for Ebury

These shifts in the Ebury group’s infection and monetization methods seem to be bearing fruit, as the group’s activity significantly increased in 2023 compared to 2021.

“The perpetrators keep track of the systems they compromised, and we used that data to draw a timeline of the number of new servers added to the botnet each month,” the ESET researchers wrote.

August 2023 saw record-breaking activity from the group, with over 6000 compromised servers recorded that month.

Combined, about 400,000 servers have been compromised by Ebury since 2009, and more than 100,000 were still compromised as of late 2023.

See also  German Police Shutter “eXch” Money Laundering Service
Botnet Crypto Diversify Ebury Financial Operators Theft
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Football Clubs Face UK FCA’s Crackdown for Promoting Unauthorized Crypto Firms

June 5, 2026

SEC Draft Plan Would Curb Enforcement Reach and Cement Atkins’s Crypto Turn

June 4, 2026

Top Crypto Events to Watch This Week Across Europe and Beyond

June 4, 2026

Standard Chartered’s three ‘Ifs’ that stand between bitcoin and a market low: Crypto Daily

June 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum Trades Sideways While Supply Dynamics Evolve—Here’s What’s Next for ETH Price

January 28, 2026

White House Weighing Candidates for Multiple CFTC Spots: Former Chairman Giancarlo

October 3, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

ENI, Noos Protocol Advance AI-Powered Coordination Layer for Decentralized Networks

June 5, 2026

As Bitcoin hangs near $61K, whale closes 1400 BTC position – Can price survive?

June 5, 2026

XRP Price Falls To 4-Month Lows—Charts Signal Sell, On-Chain Data Turns Bearish

June 5, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.