Skip to content

ESET Research: Ebury botnet alive & growing; 400k Linux servers compromised for cryptocurrency theft and financial gain

  • ESET Research has released its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing – Ebury group with their malware and botnet.
  • Over the years, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised as of late 2023.
  • Ebury actors have been pursuing monetization activities subsequent to our 2014 publication on Operation Windigo, including the spread of spam, web traffic redirections, and credential stealing.
  • Additionally, ESET has confirmed that operators are also involved in cryptocurrency heists.
  • In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers.

BRATISLAVA, MONTREALMay 14, 2024 — ESET Research released today its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing and has seen hundreds of thousands of compromised servers in its at least 15-year-long operation. Among the activities of the infamous Ebury group and botnet over the years has been the spread of spam, web traffic redirections, and credential stealing.  In recent years it has diversified to credit card and cryptocurrency theft. Additionally, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised as of late 2023. In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers.

Ten years ago, ESET published a white paper about Operation Windigo, which uses multiple malware families working in combination, with the Ebury malware family at its core. In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Netherlands national police, reached out to ESET regarding servers in the Netherlands suspected of being compromised with Ebury malware. Those suspicions turned out to be well-founded and with NHTCU’s assistance, ESET Research has gained considerable visibility into operations run by the Ebury threat actors.

“Following the release of the Windigo paper in early 2014, one of the perpetrators was arrested at the Finland-Russia border in 2015, and later extradited to the United States. While initially claiming innocence, he eventually pleaded guilty to the charges in 2017, a few weeks before his trial at the U.S. District Court in Minneapolis was set to proceed, and where ESET researchers were scheduled to testify,” says Marc-Etienne M. Léveillé, the ESET researcher who investigated Ebury for more than a decade.

Ebury, active since at least 2009, is an OpenSSH backdoor and credential stealer. It is used to deploy additional malware to: monetize the botnet (such as modules for web traffic redirection), proxy traffic for spam, perform adversary-in-the-middle attacks (AitM), and host supporting malicious infrastructure. In AitM attacks, ESET has observed over 200 targets across more than 75 networks in 34 different countries between February 2022 and May 2023.  

Its operators have used the Ebury botnet to steal cryptocurrency wallets, credentials, and credit card details. ESET has uncovered new malware families authored and deployed by the gang for financial gain, including Apache modules and a kernel module to perform web traffic redirection. Ebury operators also used zero-day vulnerabilities in administrator software to compromise servers in bulk.

After a system is compromised, a number of details are exfiltrated. Using the known passwords and keys obtained on that system, credentials are reused to try logging into related systems. Each new major version of Ebury introduces some important change and new features and obfuscation techniques.

“We have documented cases where the infrastructure of hosting providers was compromised by Ebury. In these cases, we have seen Ebury being deployed on servers rented out by those providers, with no warning to the lessees. This resulted in cases where the Ebury actors were able to compromise thousands of servers at once,” says Léveillé. There is no geographical boundary to Ebury; there are servers compromised with Ebury in almost all countries in the world. Whenever a hosting provider was compromised, it led to a vast number of compromised servers in the same data centers.

At the same time, no verticals appear more targeted than others. Victims include universities, small and large enterprises, internet service providers, cryptocurrency traders, Tor exit nodes, shared hosting providers, and dedicated server providers, to name a few.

In late 2019, the infrastructure of a large and popular US-based domain registrar and web hosting provider was compromised. In total, approximately 2,500 physical and 60,000 virtual servers were compromised by the attackers. A very large portion, if not all, of these servers are shared between multiple users to host the websites of more than 1.5 million accounts. In another incident, a total of 70,000 servers from that hosting provider were compromised by Ebury in 2023. Kernel.org, hosting the source code of the Linux kernel, had been a victim of Ebury too.

“Ebury poses a serious threat and a challenge to the Linux security community. There is no simple fix that would make Ebury ineffective, but a handful of mitigations can be applied to minimize its spread and impact. One thing to realize is that it doesn’t only happen to organizations or individuals that care less about security. A lot of very tech-savvy individuals and large organizations are among the list of victims,” concludes Léveillé.

For more technical information and a set of tools and indicators to help system administrators determine whether their systems are compromised by Ebury, read the full white paper “Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain”. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

Ebury deployments per month using two different scales on the Y axis, according to the database of compromised servers maintained by the perpetrators.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Syncro Integration Announcement

We’re pleased to announce the Syncro integration with Comet is now available. This has been a popular feature request and we are pleased that partners can now monitor their backups through Syncro’s RMM platform.

Who Is Syncro?

Syncro – Helps you scale your MSP buisness with efficiency and ease.

Transform how you manage customers and your business with RMM, PSA and remote access in a single platform. The streamlined workflow allows you to focus your time and energy on what you’re an expert in – providing solutions for your clients.

How The Syncro Integration Works

With the Syncro integration, you can access RMM alerts in Syncro’s platform when a Comet backup job fails or doesn’t run. This allows you to see your alerts in one place, rather than logging into Comet, and troubleshoot before you lose any business critical data.

If you are interested in configuring this integration, you can read our guide here.

What To Expect

When a backup job fails, a new RMM alerts will be created. You can see this on the Open RMM Alerts page in Syncro. An example of how this will look is:

If the failure is due to an intermittent issue, Comet will clear the alert when the backup job succeeds again.

This means you no longer have to login to your Comet Server to check if backup jobs are running successfully or not.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

ESET Research: Russia-aligned Turla group likely uses Lunar arsenal to target & spy on European diplomats

  • ESET Research discovered two previously unknown backdoors — which we named LunarWeb and LunarMail — compromising a European ministry of foreign affairs and its diplomatic missions abroad, primarily in the Middle East.
  • ESET researchers attribute these compromises with medium confidence to the infamous Russia-aligned cyberespionage group Turla. The aim of the campaign is cyberespionage.
  • Turla, also known as Snake, has been active since at least 2004, possibly even dating back to the late 1990s. It is believed to be part of the Russian FSB.
  • ESET believes that the Lunar toolset has been in use since at least 2020.
  • Both backdoors employ steganography, a technique in which commands are hidden in images to avoid detection.
BRATISLAVAMay 15, 2024 — ESET Research discovered two previously unknown backdoors — which we named LunarWeb and LunarMail — compromising a European ministry of foreign affairs and its diplomatic missions abroad, primarily in the Middle East. ESET believes that the Lunar toolset has been used since at least 2020 and, given the similarities between the tactics, techniques, and procedures and past activities, ESET researchers attribute these compromises with medium confidence to the infamous Russia-aligned cyberespionage group Turla. The aim of the campaign is cyberespionage. The ESET investigation began with the detection of a loader deployed on an unidentified server, which decrypts and loads a payload from a file. This led ESET researchers to the discovery of a previously unknown backdoor, which ESET named LunarWeb. Subsequently, a similar chain with LunarWeb deployed at a diplomatic mission was detected. Notably, the attacker also included a second backdoor — which ESET named LunarMail — that uses a different method for command and control (C&C) communications. During another attack, ESET observed simultaneous deployments of a chain with LunarWeb at three diplomatic missions of a European country in the Middle East, occurring within minutes of each other. The attacker probably had prior access to the domain controller of the ministry of foreign affairs and utilized it for lateral movement to machines of related institutions in the same network. LunarWeb, deployed on servers, uses HTTP(S) for its C&C communications and mimics legitimate requests, while LunarMail, deployed on workstations, persists as an Outlook add-in and uses email messages for its C&C communications. Both backdoors employ steganography, a technique in which commands are hidden in images to avoid detection. Their loaders can exist in various forms, including trojanized open-source software, demonstrating the advanced techniques used by the attackers. “We observed varying degrees of sophistication in the compromises — for example, the careful installation on the compromised server to avoid scanning by security software contrasted with coding errors and different coding styles of the backdoors. This suggests multiple individuals were probably involved in the development and operation of these tools,” says ESET researcher Filip Jurčacko, who discovered the Lunar toolset. Recovered installation-related components and attacker activity suggest that possible initial compromise happened via spearphishing and abuse of misconfigured network and application monitoring software Zabbix. Furthermore, the attacker already had network access, used stolen credentials for lateral movement, and took careful steps to compromise the server without raising suspicion. In another compromise, researchers found an older malicious Word document, likely from a spearphishing email. LunarWeb collects and exfiltrates information from the system, such as computer and operating system information, a list of running processes, a list of services, and a list of installed security products.  LunarWeb supports common backdoor capabilities, including file and process operations, and running shell commands. On first run, the LunarMail backdoor collects information from recipients’ sent email messages (email addresses). In terms of command capabilities, LunarMail is simpler and features a subset of the commands found in LunarWeb. It can write a file, create a new process, take a screenshot, and modify the C&C communication email address. Both backdoors have the unusual capability of being able to execute Lua scripts. Turla, also known as Snake, has been active since at least 2004, possibly even dating back to the late 1990s. Believed to be part of the Russian FSB, Turla mainly targets high-profile entities such as governments and diplomatic organizations in Europe, Central Asia, and the Middle East. The group is notorious for breaching major organizations, including the US Department of Defense in 2008 and the Swiss defense company RUAG in 2014. For more technical information about the Lunar toolset, read the blogpost “To the Moon and back(doors): Lunar landing in diplomatic missions.” Make sure to follow ESET Research on Twitter (today known as X) for the latest news.

Illustration of an exfiltration email with data hidden in the image

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET included among notable vendors in Mobile Threat Defense Solutions Landscape report

BRATISLAVAMay 9, 2024ESET, a global leader in cybersecurity solutions, has been included in Forrester’s Mobile Threat Defense (MTD) Solutions Landscape report, Q1 2024. Forrester, a respected analyst firm, provides an overview of 16 vendors in the field, including ESET, which, in our opinion, makes ESET a valuable player in this established market.

The importance of mobile malware protection is highlighted in the Forrester’s MTD Solutions Landscape report,1 which states: “Mobile devices are just as vulnerable to attacks as traditional endpoints like laptops and servers, whether through malicious applications, operating system (OS) vulnerabilities, phishing through messaging applications unique to mobile devices, or web-based attacks.” The report also emphasizes the comprehensive capabilities of MTD solutions designed to protect mobile devices with a level of rigor traditionally reserved for enterprises.

This inclusion comes shortly after the successful launch of the ESET’s Mobile Threat Defense module, a testament to ESET’s commitment to advancing mobile security. The module integrates seamlessly with the ESET PROTECT Platform, ensures comprehensive coverage of the mobile fleet attack vector with a one-to-one ratio to endpoints, and is included in all cloud subscription tiers starting from ESET PROTECT Advanced with no increase in price. This integration ensures unified security management and eliminates the need to juggle multiple consoles or platforms.

“The recognition in Forrester’s MTD Solutions Landscape report underscores for us the necessity of robust mobile threat defense in today’s security ecosystem,” explained Jakub Debski, Chief Product Officer at ESET. “With remote work expanding the scope of corporate networks, mobile devices have become prime targets for attackers. Our Mobile Threat Defense module not only addresses traditional threats but also adapts to the unique characteristics and challenges of mobile platforms, offering a solution that is both comprehensive and compliant with the evolving market needs.”

The report outlines three core and five extended use cases that underline the critical focus areas for organizations looking to strengthen their mobile security. Support for remote work, bring your own device policies, and mobile app security has been identified as core use cases, which are primary buyer expectations. Beyond these, the analysts have noted extended use cases like compliance assurance, contractor security, executive protection, and Zero Trust endpoint security. While not all MTD solutions cover these extended areas, they represent growing buyer interests alongside the core functionalities. ESET self-reported the extended use cases of compliance assurance, executive protection, and mobile knowledge worker as the top use cases for which clients select them.

For more information about ESET and its recently launched ESET Mobile Threat Defense module, please read here. The full report is available to Forrester clients with a valid subscription or for purchase.

1Forrester: Mobile Threat Defense Solutions Landscape, Q1 2024. Paddy Harrington and Team. March 18, 2024

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Scale Computing Recognized as a Representative Vendor in the 2024 Gartner® Market Guide for Edge Computing

Access the Complimentary Report to Learn More About the Edge Computing Market Guide

INDIANAPOLIS – May 7, 2024 — Scale Computing, a market leader in edge computing, virtualization, and hyperconverged solutions, today announced that it has been recognized as Representative Vendor in the 2024 Gartner® Market Guide for Edge Computing for its Scale Computing//Fleet Manager (SC//Fleet Manager) solution. Now in its second year, the Market Guide for Edge Computing examines the edge computing market and provides an in-depth analysis of the many facets of edge computing solutions.

Edge computing brings computing resources closer to the source of data generation or consumption, reducing latency and bandwidth issues and improving overall system performance. By processing data at the edge, near where it is created, organizations can achieve real-time responsiveness, faster decision-making, and a seamless user experience. By 2027, Gartner predicts that 20% of large enterprises will deploy an edge management and orchestration solution, compared with fewer than 1% in 2023.*

“Edge computing has grown tremendously in recent years, and it shows no signs of slowing down,” said Jeff Ready, CEO and co-founder, Scale Computing. “IT leaders across industries are recognizing the need for powerful and reliable data processing at the edge, and this drive for real-time response for mission-critical applications is fueling rapid edge adoption. Scale Computing has been at the forefront of this movement, empowering organizations with industry-leading edge management and orchestration solutions that are efficient, scalable, secure, and reliable. We’re proud ​​to be recognized by Gartner in this exciting space.”

Scale Computing brings together simplicity and scalability with an edge computing platform that is easy to use, easy to manage, and easy to deploy. Scale Computing Platform (SC//Platform) replaces existing infrastructure, empowering enterprises to run applications and process data outside centralized data centers, at the edge of their networks, closest to where data is created and utilized. With SC//Fleet Manager, the industry’s first cloud-hosted monitoring and management tool built for hyperconverged edge computing infrastructure at scale, customers can quickly identify areas of concern using a single pane of glass, scaling from 1 to over 50,000 clusters. Zero-touch provisioning allows administrators to centrally monitor and manage hundreds or thousands of distributed edge infrastructure deployments with few or no on-site IT personnel.

Gartner Market Guides define emerging markets and explain what clients can expect those markets to do in the short term. They can help IT and strategic leaders and investors to gain a broad view across multiple markets, including mature and smaller markets, in an easy-to-read format. The 2024 Gartner Market Guide for Edge Computing discusses the importance of edge management and orchestration today and describes vendor strategies and offerings that support edge computing. It outlines predictions for the edge market’s future, including offerings, frameworks, capabilities, and functionalities, and offers recommendations for I&O leaders responsible for implementing edge computing projects.

To learn more about Scale Computing and gain complimentary access to the 2024 Gartner® Market Guide for Edge Computing, please visit the Scale Computing website.

*Gartner, “Market Guide for Edge Computing”, March 12, 2024.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×