Skip to content

ESET and Dutch police expose Ebury botnet’s cryptocurrency theft operations

Dutch cybersecurity experts, in collaboration with ESET, have linked a significant cryptocurrency theft to the Ebury botnet, notorious for compromising over 400,000 servers in 15 years. This discovery, made during a 2021 investigation by the Dutch National High Tech Crime Unit, marks the first time the botnet was observed targeting cryptocurrency, notably Bitcoin and Ethereum wallets. Ebury stands out for employing an adversary-in-the-middle attack to intercept and steal cryptocurrency, a sophisticated technique not previously associated with the botnet.

With over 100,000 servers still infected as of 2023, the scale of Ebury’s impact is significant, showcasing its ability to adapt and target financial assets directly. The arrest and conviction of one operator, Maxim Senakh, underscores the international effort to dismantle this network. This ongoing battle against Ebury highlights the evolving nature of cyber threats and the critical importance of international cooperation in cybersecurity.

For more details, visit the original reports on ESET and the U.S. Department of Justice’s website.

Share