Skip to content

Malware

Ebury

This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers.

Ebury is a Linux malware family.

Background

This payload was behind the August 2011 compromise of kernel.org and also struck cPanel Support, which in turn led to numerous cPanel servers being infected. It is a credential-stealing payload that captures SSH keys, passwords, and possibly other credentials.

The family belongs to a broader set of tools documented in detail in ESET's Operation Windigo whitepaper.


Source: Malpedia (Fraunhofer FKIE).