{"id":115822,"date":"2024-05-16T08:59:20","date_gmt":"2024-05-16T06:59:20","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym"},"modified":"2024-05-16T08:59:20","modified_gmt":"2024-05-16T06:59:20","slug":"ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym","title":{"rendered":"An SSH backdoor installed during the hack of kernel.org went undetected for two years.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Researchers from ESET published a 43-page report analyzing the Ebury rootkit and related activities. It is claimed that Ebury has been in use since 2009 and has since been installed on more than 400,000 Linux servers and several hundred systems based on FreeBSD, OpenBSD, and Solaris. Approximately 110,000 servers remained compromised by Ebury as of the end of 2023. The study is of particular interest given that Ebury was involved in the attack on kernel.org, revealing new details about the compromise of the Linux kernel development infrastructure identified in 2011. Ebury was also detected on domain registrar servers, cryptocurrency exchanges, Tor exit nodes, and several <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/\"   title=\"hosting providers\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1211\">hosting providers<\/a>, whose names are not disclosed.    <\/p>\n<p>Initially, it was assumed that the attackers <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/\"   title=\"servers\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1907\">servers<\/a> Attackers remained undetected on kernel.org for 17 days, but according to ESET, this duration is calculated from the moment the Phalanx rootkit was inserted, while the Ebury backdoor had been on servers since 2009 and could have been used for root access for about two years. The Ebury and Phalanx malware were deployed as part of different, non-overlapping attacks conducted by various hacker groups. The Ebury backdoor affected at least 4 servers within the kernel.org infrastructure, two of which were compromised for approximately two years, while the other two were compromised for 6 months.    <\/p>\n<p>The attackers gained access to hashed passwords of 551 users stored in \/etc\/shadow, among whom were all the kernel maintainers (the accounts were used to access Git; after the incident, passwords were changed, and the access model was revised and transitioned to the use of digital signatures). For 257 users, the attackers managed to determine passwords in plain text, presumably through brute-forcing hashes and via interception of passwords used in SSH by the malicious component Ebury.    <\/p>\n<p>The malicious component Ebury was spread as a shared library, which, after installation, intercepted functions used in OpenSSH to establish remote connections to the system with root privileges. The attack was non-targeted, and like other thousands of affected hosts, the kernel.org servers were used as part of a botnet for spamming, credential theft to spread to other systems, redirecting web traffic, and carrying out other malicious activities.       <\/p>\n<p>To penetrate the servers, unpatched vulnerabilities in the server software were exploited, such as vulnerabilities in hosting panels, or intercepted passwords (it is assumed that the kernel.org servers were compromised due to the password compromise of a user with shell access). Privilege escalation was achieved using vulnerabilities like Dirty COW.     <\/p>\n<p> The new versions of Ebury used in recent years, in addition to the backdoor, included features such as modules for Apache httpd for traffic proxying, redirecting users, and intercepting sensitive information, a kernel module to alter transit HTTP traffic, tools to hide its own traffic from firewalls, and scripts for conducting AitM attacks (Adversary-in-the-Middle, bi-directional MiTM) to capture SSH credentials in hosting provider networks.    <center><img decoding=\"async\" alt=\"An SSH backdoor installed during the hack of kernel.org went undetected for two years.\" src=\"\/wp-content\/uploads\/2024\/05\/d11006ed93b6c8413d2e8f3ae7846dab.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=61186\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 43-\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0439 \u043e\u0442\u0447\u0451\u0442 \u0441 \u0430\u043d\u0430\u043b\u0438\u0437\u043e\u043c \u0440\u0443\u0442\u043a\u0438\u0442\u0430 Ebury \u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043d\u0438\u043c \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438. \u0423\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u0435\u0442\u0441\u044f, \u0447\u0442\u043e Ebury \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u0441 2009 \u0433\u043e\u0434\u0430 \u0438 \u0441 \u0442\u0435\u0445 \u043f\u043e\u0440 \u0431\u044b\u043b \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d \u043d\u0430 \u0431\u043e\u043b\u0435\u0435 \u0447\u0435\u043c 400 \u0442\u044b\u0441\u044f\u0447 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043f\u043e\u0434 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c Linux \u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043e\u0442\u0435\u043d \u0441\u0438\u0441\u0442\u0435\u043c \u043d\u0430 \u0431\u0430\u0437\u0435 FreeBSD, OpenBSD \u0438 Solaris. \u041e\u043a\u043e\u043b\u043e 110 \u0442\u044b\u0441\u044f\u0447 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0440\u0430\u0436\u0435\u043d\u044b Ebury [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":115823,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-115822","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 43-\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0439 \u043e\u0442\u0447\u0451\u0442 \u0441 \u0430\u043d\u0430\u043b\u0438\u0437\u043e\u043c \u0440\u0443\u0442\u043a\u0438\u0442\u0430 Ebury \u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043d\u0438\u043c \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47SSH-\u0431\u044d\u043a\u0434\u043e\u0440, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u043f\u0440\u0438 \u0432\u0437\u043b\u043e\u043c\u0435 kernel.org, \u0434\u0432\u0430 \u0433\u043e\u0434\u0430 \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0441\u044f \u043d\u0435\u0437\u0430\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 43-\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0439 \u043e\u0442\u0447\u0451\u0442 \u0441 \u0430\u043d\u0430\u043b\u0438\u0437\u043e\u043c \u0440\u0443\u0442\u043a\u0438\u0442\u0430 Ebury \u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043d\u0438\u043c \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-05-16T06:59:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-05-16T06:59:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The SSH backdoor installed during the kernel.org hack remained unnoticed for two years | ProHoster","description":"Researchers from ESET published a 43-page report analyzing the Ebury rootkit and its associated activities.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47SSH-\u0431\u044d\u043a\u0434\u043e\u0440, \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u043f\u0440\u0438 \u0432\u0437\u043b\u043e\u043c\u0435 kernel.org, \u0434\u0432\u0430 \u0433\u043e\u0434\u0430 \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0441\u044f \u043d\u0435\u0437\u0430\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u043c | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 ESET \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 43-\u0441\u0442\u0440\u0430\u043d\u0438\u0447\u043d\u044b\u0439 \u043e\u0442\u0447\u0451\u0442 \u0441 \u0430\u043d\u0430\u043b\u0438\u0437\u043e\u043c \u0440\u0443\u0442\u043a\u0438\u0442\u0430 Ebury \u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u043e\u0439 \u0441 \u043d\u0438\u043c \u0430\u043a\u0442\u0438\u0432\u043d\u043e\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/ssh-bekdor-ustanovlennyj-pri-vzlome-kernel-org-dva-goda-ostavalsya-nezamechennym","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-05-16T06:59:20+00:00","article:modified_time":"2024-05-16T06:59:20+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"115822","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 17:22:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 00:28:19","updated":"2026-02-09 17:22:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/115822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=115822"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/115822\/revisions"}],"predecessor-version":[{"id":159151,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/115822\/revisions\/159151"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/115823"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=115822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=115822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=115822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}