Ebury Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 29, 2025
Last Seen
January 30, 2026

Ebury is a malware family tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 29, 2025; most recent activity January 30, 2026.

Overview

Ebury is a Linux/Unix malware family known for stealthily stealing SSH credentials and private keys to pivot across compromised hosts. It enables long-term persistence and lateral movement by abusing stolen credentials, highlighting the risk of credential exposure in enterprise environments. Its significance lies in how credential theft can unlock widespread access with relatively low technical overhead for attackers.

Related Threat Clusters

  • ShadowHS Malware Framework Targets Linux Systems with Fileless Techniques

    The ShadowHS malware framework has been identified as a significant threat to Linux environments, utilizing a fileless architecture for stealthy operations. Discovered by Cyble Research & Intelligence Labs on January…

    4 articles · Updated February 4, 2026
  • Identity Compromises Drive Surge in Cloud Attacks in Q3 2025

    A report from ReliaQuest reveals that 44% of true-positive alerts in Q3 2025 were linked to identity-related weaknesses, such as excessive permissions and credential abuse. As organizations migrate assets to cloud…

    6 articles · Updated November 29, 2025
  • Identity Compromises Drive Surge in Cloud Attacks

    A report from ReliaQuest reveals that 99% of cloud accounts are over-privileged, leading to a rise in identity-related attacks. In Q3 2025, identity compromises accounted for 44% of true-positive alerts, primarily due…

    1 article · Updated November 6, 2025

Recent Intelligence Reports

  • Cyble Research Discovers ShadowHS, an In-Memory Linux Framework for Long — Thecyberexpress · January 30, 2026
  • Identity is the New Perimeter: How Exposed Accounts Forecast Incidents — Thefastmode · November 29, 2025

CVSS v3.1 Breakdown