• Thousands of Linux servers infected by Ebury malware

    From TechnologyDaily@1337:1/100 to All on Wed May 15 12:15:04 2024
    Thousands of Linux servers infected by Ebury malware

    Date:
    Wed, 15 May 2024 12:00:41 +0000

    Description:
    More than 100,000 servers are still compromised by a decades-old infostealer.

    FULL STORY ======================================================================

    Thousands of Linux servers are still infected by Ebury, a decades-old information-stealing malware that was thought extinct.

    Ebury is a sophisticated piece of malware designed to compromise Linux-based systems, particularly servers. It's a type of backdoor and
    credential-stealing malware that allows attackers to gain unauthorized access to compromised systems.

    Ebury's developers are financially motivated, in newer times expanding into the cryptocurrency space, as well. Ebury also seems to be used for spam and web traffic redirection. Targeting hosting providers

    When cybersecurity researchers from ESET first reported on Ebury a decade
    ago, the report resulted in the arrest of the malwares operators. However, that didnt stop the malware from being updated and growing in the years
    since. Cumulatively, since 2009, some 400,000 Linux-powered servers have been infected by this backdoor.

    At the end of last year, more than 100,000 endpoints were thought to still carrying the infection, according to a follow-up report (PDF) that ESET published earlier this week.

    Key Ebury victims seem to be hosting providers, the researchers found. The gang leverages its access to the hosting providers infrastructure to install Ebury on all the servers that are being rented by that provider, they explained. As part of an experiment, they rented a virtual server and
    suffered an infection within a week.

    Another interesting method is the use of adversary in the middle to intercept SSH traffic of interesting targets inside data centers and redirect it to a server used to capture credentials, they added.

    Last year, more than 200 servers were targeted by Ebury operators. Among the targets were many Bitcoin and Ethereum nodes, as one of Eburys main features was to automatically steal cryptocurrency wallets hosted on the targeted server, as soon as the victim logs in with a password.

    Via BleepingComputer More from TechRadar Pro A whole new kind of Linux malware has been found in the wild Here's a list of the best firewalls today These are the best endpoint protection tools right now



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/thousands-of-linux-servers-infected-by- ebury-malware


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)