1
Groups Using This
1
Platforms
298
Prevalence Rank
0
Known Aliases
Description

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.

View MITRE record ↗

Platforms
Linux
Groups Deploying Ebury (1)
↑