ATT&CKReferencesESET Ebury May 2024

ESET Ebury May 2024

Marc-Etienne M.Léveillé. (2024, May 1). Ebury is alive but unseen. Retrieved May 21, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1020
Automated Exfiltration
MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1041
Exfiltration Over C2 Channel
MalwareEbury

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1059.004
Unix Shell
MalwareEbury

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1129
Shared Modules
MalwareEbury

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1554
Compromise Host Software Binary
MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1574.006
Dynamic Linker Hijacking
MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

T1685.004
Disable or Modify Linux Audit System Log
MalwareEbury

Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.