Ebury

S0377

Malware.View on attack.mitre.org

About this malware

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1008
Fallback Channels

Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days.

T1014
Rootkit

Ebury acts as a user land rootkit using the SSH service.

T1020
Automated Exfiltration

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1027
Obfuscated Files or Information

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1041
Exfiltration Over C2 Channel

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1059.004
Unix Shell

Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level.

T1059.006
Python

Ebury has used Python to implement its DGA.

T1071.004
DNS

Ebury has used DNS requests over UDP port 53 for C2.

T1129
Shared Modules

Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`.

T1132.001
Standard Encoding

Ebury has encoded C2 traffic in hexadecimal format.

T1140
Deobfuscate/Decode Files or Information

Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key.

T1552.004
Private Keys

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1553.002
Code Signing

Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems.

T1554
Compromise Host Software Binary

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1556
Modify Authentication Process

Ebury can intercept private keys using a trojanized ssh-add function.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. BleepingComputer Ebury March 2017 Open source
    Cimpanu, C.. (2017, March 29). Russian Hacker Pleads Guilty for Role in Infamous Linux Ebury Malware. Retrieved April 23, 2019.
  2. ESET Ebury Feb 2014 Open source
    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.
  3. ESET Ebury May 2024 Open source
    Marc-Etienne M.Léveillé. (2024, May 1). Ebury is alive but unseen. Retrieved May 21, 2024.
  4. ESET Ebury Oct 2017 Open source
    Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.