Malware.View on attack.mitre.org
Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days. |
| T1014 Rootkit |
Ebury acts as a user land rootkit using the SSH service. |
| T1020 Automated Exfiltration |
If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| T1027 Obfuscated Files or Information |
Ebury has obfuscated its strings with a simple XOR encryption with a static key. |
| T1041 Exfiltration Over C2 Channel |
Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server. |
| T1059.004 Unix Shell |
Ebury can use the commands `Xcsh` or `Xcls` to open a shell with Ebury level permissions and `Xxsh` to open a shell with root level. |
| T1059.006 Python |
Ebury has used Python to implement its DGA. |
| T1071.004 DNS |
Ebury has used DNS requests over UDP port 53 for C2. |
| T1129 Shared Modules |
Ebury is executed through hooking the keyutils.so file used by legitimate versions of `OpenSSH` and `libcurl`. |
| T1132.001 Standard Encoding |
Ebury has encoded C2 traffic in hexadecimal format. |
| T1140 Deobfuscate/Decode Files or Information |
Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key. |
| T1552.004 Private Keys |
Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| T1553.002 Code Signing |
Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems. |
| T1554 Compromise Host Software Binary |
Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1556 Modify Authentication Process |
Ebury can intercept private keys using a trojanized |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.