Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

June 25, 2026

Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

June 25, 2026

Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

June 25, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    2026 not the same as 2024 because long-term Bitcoin holders are ‘doing the opposite’

    June 25, 2026

    Bitcoin Crashes: A Historical Overview

    June 25, 2026

    Citi Strategist Scott Chronert Details ‘Barbell’ Strategy To Capture AI and Broadening out Trades

    June 25, 2026

    Blackrock Moves $256 Million in BTC & ETH To Coinbase, Selling Pressure Ahead?

    June 24, 2026

    Can Whale Buying Offset ETF Outflows?

    June 24, 2026

    Why whales are buying Ethereum’s dip despite weak price action and ETF outflows

    June 24, 2026

    Ethereum USD Price Remains Stuck Below $1,800 as Bullish Momentum Fades

    June 24, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026

    DOJ Seizes Huione Cloud Backbone In Crypto Scam Money-Laundering Crackdown

    June 25, 2026

    SBI And Startale Put Yen Stablecoins Back In The Institutional Spotlight

    June 25, 2026

    Meta Prediction Market App Push Puts Polymarket Model In Big Tech Spotlight

    June 24, 2026

    Dogecoin Cash Files U.S. Patent for DOGP Blockchain Framework

    June 15, 2026

    How SIREN Went From AI Memecoin to Boom-and-Bust

    June 8, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Merck and Hashgraph Group launch Hedera-based product passport for EU compliance

    June 12, 2026

    COTI and Midnight Foundation Partner to Advance the Global Privacy Ecosystem

    June 11, 2026

    Cardano Gets Exposure From Olympics Committee

    June 11, 2026

    How Privacy and Composability Trade-Offs Differ

    June 11, 2026

    Microsoft Warns of New USB-Based Malware Targeting Crypto Users

    June 21, 2026

    Fake GitHub Stars and AI Videos Mask a Crypto Clipper

    June 18, 2026

    Zcash Climbs 80% Since June 5 as Traders Shrug off Orchard Bug Fears – Bitcoin News

    June 18, 2026

    Rokarolla Trojan Combines Banking Fraud With Device Surveillance

    June 16, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026
  • Web 3
    1. Gaming
    2. View All

    Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

    June 23, 2026

    Nexus Acquires Homegrown App Marketplace One Store, Expanding into Global Web3 Game Hub

    June 21, 2026

    GoMining Rolls Out GoBTC Pay SDK for Bitcoin Merchant Payments

    June 20, 2026

    Real Finance Launches $ASSET Rewards Campaign to Support RWA Ecosystem Growth

    June 19, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Crypto finally has a CLARITY Act date – delivery now depends on seven Senate Democrats

    June 24, 2026

    US Treasury’s $10B scam warning shows why crypto is racing to police itself

    June 24, 2026

    Centralized Wall Street gatekeepers to control investors’ route into tokenized stocks through old pipes

    June 23, 2026

    Europe’s Swedish krona stablecoin arrives with a warning: dollar liquidity may already be too far ahead

    June 22, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Latest bear market victim shows how quickly DeFi users are left behind when crypto projects move on

    June 24, 2026

    South Korean digital bank with 15M users turns to Solana stablecoins for overseas transfers

    June 24, 2026

    Ripple gives RLUSD a MiCA foothold in Europe and route into African payments

    June 23, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026
  • Analysis

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    AAVE Price Rallies 16% as $3,500 Prediction Fuels DeFi Rally

    June 25, 2026

    Tokenized SpaceX stocks hit by $50M in liquidations as crypto leverage reaches Wall Street

    June 25, 2026

    Why viral public whale liquidations are becoming a real trading signal on Hyperliquid

    June 25, 2026

    Saylor’s STRC Bitcoin machine is turning shareholders into its cash backstop

    June 25, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    HYPE ETFs quietly pulled $161M in one month as Wall Street buys crypto’s on-chain exchange bet

    June 15, 2026

    Crypto exchanges are opening a two-front war for the stock market

    June 12, 2026

    Crypto’s killer app may be selling stocks after its own tokens failed retail

    June 10, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

    June 25, 2026

    Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

    June 25, 2026

    World Network Agentkit Links Verified Humans To Autonomous AI Agents

    June 25, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Ebury Botnet Operators Diversify with Financial and Crypto Theft
Ebury Botnet Operators Diversify with Financial and Crypto Theft
Security and Privacy

Ebury Botnet Operators Diversify with Financial and Crypto Theft

September 22, 2025No Comments5 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Ebury, one of the most advanced server-side malware campaigns, has been active for 15 years but its use by threat actors is still growing, according to cybersecurity firm ESET.

A new report published on May 14 by ESET Research showed that operators of the Ebury malware and botnet were more active than ever in 2023.

Over the years, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD and OpenBSD servers. More than 100,000 were still compromised as of late 2023.

Long known to deploy spam, web traffic redirections and credential stealing, the Ebury group recently added credit card compromise and cryptocurrency theft in its techniques, tactics and procedures (TTPs).

What is the Ebury Botnet?

Ebury is a malicious group that has been active since at least 2009. It has developed an OpenSSH backdoor and a credential stealer used to deploy multiple malware strains simultaneously by relying on a bot network (botnet).

The group’s primary targets are hosting providers.

The Ebury botnet is used to compromise Linux, FreeBSD and OpenBSD servers in order to deploy web traffic redirection modules, proxy traffic for spam or perform adversary-in-the-middle attacks (AitM).

In 2014, ESET published a white paper about Operation Windigo, a malicious campaign using multiple malware families working in combination with the Ebury malware family at its core.

Following the release of the Windigo paper, Russian national Maxim Senakh, one of the Ebury operators, was arrested at the Finland-Russia border in 2015, and later extradited to the US.

In 2017, he was sentenced to 46 months in prison in the US for his role in running the Ebury botnet. ESET assisted the FBI in the operation and testified during the trial.

See also  Why is crypto going up today? Fed rate cut bets, ETF inflows & more...

In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Netherlands national police, contacted ESET after they had found Ebury on the server of a victim of cryptocurrency theft.

“Those suspicions turned out to be well-founded and with NHTCU’s assistance, ESET Research has gained considerable visibility into operations run by the Ebury threat actors,” the new ESET report indicated.

Marc-Etienne M. Léveillé, the ESET researcher who investigated Ebury for more than a decade, commented: “We have documented cases […] where the Ebury actors were able to compromise thousands of servers at once. There is no geographical boundary to Ebury; there are servers compromised with Ebury in almost all countries in the world. Whenever a hosting provider was compromised, it led to a vast number of compromised servers in the same data centers.

“At the same time, no verticals appear more targeted than others. Victims include universities, small and large enterprises, internet service providers, cryptocurrency traders, Tor exit nodes, shared hosting providers and dedicated server providers, to name a few.”

Ebury’s New Favorite Targets: Bitcoin and Ethereum Nodes

Despite the arrest, the Ebury group has continued running malicious campaigns, at least until late 2023.

The ESET report describes new methods used to propagate Ebury to new servers that appeared after 2021.

From its access to its target’s infrastructure, usually a hosting provider, the Ebury group can deploy several types of attacks.

In one of the most recent ones, the group uses an AitM attack to intercept SSH traffic of attractive targets inside data centers and redirect it to a server used to capture credentials.

See also  Legislation Steering U.S. Fate of Crypto Emerges in New Version in Senate

The malicious actors leverage existing Ebury-compromised servers in the same network segment as their target to perform Address Resolution Protocol (ARP) spoofing. Among the targets are Bitcoin and Ethereum nodes. Ebury automatically steals cryptocurrency wallets hosted on the targeted server once the victim types the password to log into it.

ESET has observed that this method was used to target over 200 targets across over 75 networks in 34 countries between February 2022 and May 2023. 

This example not only illustrates one of Ebury’s latest attack techniques, but also one of the group’s newest vectors of monetization: cryptocurrency theft.

Additionally, the Ebury malware family itself has also been updated.

The new major version update, 1.8, first seen in late 2023, included new obfuscation techniques, a new domain generation algorithm (DGA) and improvements in the userland rootkit used by Ebury to hide itself from system administrators. When active, the process, the file, the socket and even the mapped memory are hidden.

2023, a Record-Breaking Year for Ebury

These shifts in the Ebury group’s infection and monetization methods seem to be bearing fruit, as the group’s activity significantly increased in 2023 compared to 2021.

“The perpetrators keep track of the systems they compromised, and we used that data to draw a timeline of the number of new servers added to the botnet each month,” the ESET researchers wrote.

August 2023 saw record-breaking activity from the group, with over 6000 compromised servers recorded that month.

Combined, about 400,000 servers have been compromised by Ebury since 2009, and more than 100,000 were still compromised as of late 2023.

See also  FileFix Campaign Using Steganography and Multistage Payloads
Botnet Crypto Diversify Ebury Financial Operators Theft
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Tokenized SpaceX stocks hit by $50M in liquidations as crypto leverage reaches Wall Street

June 25, 2026

DOJ Seizes Huione Cloud Backbone In Crypto Scam Money-Laundering Crackdown

June 25, 2026

Crypto finally has a CLARITY Act date – delivery now depends on seven Senate Democrats

June 24, 2026

US Treasury’s $10B scam warning shows why crypto is racing to police itself

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Did the Texas Senate Approve the ‘XRP Reserve Bill’ to Buy $100 Million in XRP Annually?

September 30, 2025

Where will Ethereum go next? PayPal’s expanding PYUSD supply may have the answer!

September 11, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

June 25, 2026

Strategy Craters 10%, Hits 2-Year Low As BTC Falls To $59K

June 25, 2026

Goldman Sachs Names Three Reasons $700,000,000 in IPOs and Follow-On Issuances Won’t Overwhelm the Stock Market

June 25, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.