• bitcoinBitcoin (BTC) $ 66,551.00
  • ethereumEthereum (ETH) $ 3,598.89
  • tetherTether (USDT) $ 0.999343
  • bnbBNB (BNB) $ 608.56
  • solanaSolana (SOL) $ 149.22
  • staked-etherLido Staked Ether (STETH) $ 3,597.52
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.489258
  • dogecoinDogecoin (DOGE) $ 0.136114
  • the-open-networkToncoin (TON) $ 8.02
  • cardanoCardano (ADA) $ 0.416103
  • shiba-inuShiba Inu (SHIB) $ 0.000021
  • avalanche-2Avalanche (AVAX) $ 29.86
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 66,661.00
  • tronTRON (TRX) $ 0.116645
  • chainlinkChainlink (LINK) $ 15.10
  • polkadotPolkadot (DOT) $ 6.38
  • uniswapUniswap (UNI) $ 11.59
  • bitcoin-cashBitcoin Cash (BCH) $ 427.81
  • nearNEAR Protocol (NEAR) $ 5.65
  • litecoinLitecoin (LTC) $ 78.71
  • matic-networkPolygon (MATIC) $ 0.619790
  • wrapped-eethWrapped eETH (WEETH) $ 3,743.03
  • leo-tokenLEO Token (LEO) $ 5.90
  • daiDai (DAI) $ 0.998750
  • pepePepe (PEPE) $ 0.000012
  • internet-computerInternet Computer (ICP) $ 9.43
  • kaspaKaspa (KAS) $ 0.157411
  • ethereum-classicEthereum Classic (ETC) $ 25.47
  • fetch-aiFetch.ai (FET) $ 1.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,580.47
  • aptosAptos (APT) $ 7.87
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • moneroMonero (XMR) $ 177.51
  • render-tokenRender (RNDR) $ 8.35
  • hedera-hashgraphHedera (HBAR) $ 0.085787
  • filecoinFilecoin (FIL) $ 5.25
  • mantleMantle (MNT) $ 0.897419
  • stellarStellar (XLM) $ 0.098740
  • cosmosCosmos Hub (ATOM) $ 7.21
  • blockstackStacks (STX) $ 1.90
  • okbOKB (OKB) $ 45.89
  • arbitrumArbitrum (ARB) $ 0.922335
  • crypto-com-chainCronos (CRO) $ 0.098680
  • dogwifcoindogwifhat (WIF) $ 2.58
  • immutable-xImmutable (IMX) $ 1.70
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999934
  • injective-protocolInjective (INJ) $ 25.04
  • suiSui (SUI) $ 0.955788
  • optimismOptimism (OP) $ 2.09
  • makerMaker (MKR) $ 2,431.60
  • the-graphThe Graph (GRT) $ 0.235681
  • vechainVeChain (VET) $ 0.029502
  • bittensorBittensor (TAO) $ 307.06
  • notcoinNotcoin (NOT) $ 0.020065
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,992.40
  • flokiFLOKI (FLOKI) $ 0.000205
  • lido-daoLido DAO (LDO) $ 2.16
  • arweaveArweave (AR) $ 28.42
  • jasmycoinJasmyCoin (JASMY) $ 0.037375
  • fantomFantom (FTM) $ 0.636547
  • ondo-financeOndo (ONDO) $ 1.18
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,723.52
  • theta-tokenTheta Network (THETA) $ 1.69
  • bonkBonk (BONK) $ 0.000025
  • bitget-tokenBitget Token (BGB) $ 1.15
  • thorchainTHORChain (RUNE) $ 4.66
  • celestiaCelestia (TIA) $ 8.06
  • based-brettBrett (BRETT) $ 0.155771
  • coredaoorgCore (CORE) $ 1.63
  • whitebitWhiteBIT Coin (WBT) $ 9.61
  • eosEOS (EOS) $ 0.652349
  • pyth-networkPyth Network (PYTH) $ 0.361950
  • aaveAave (AAVE) $ 85.35
  • sei-networkSei (SEI) $ 0.414000
  • algorandAlgorand (ALGO) $ 0.154502
  • ethenaEthena (ENA) $ 0.763260
  • jupiter-exchange-solanaJupiter (JUP) $ 0.914558
  • starknetStarknet (STRK) $ 0.931193
  • quant-networkQuant (QNT) $ 82.95
  • galaGALA (GALA) $ 0.033015
  • cheeleeCheelee (CHEEL) $ 20.54
  • flare-networksFlare (FLR) $ 0.027099
  • gatechain-tokenGate (GT) $ 8.58
  • flowFlow (FLOW) $ 0.720216
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,632.21
  • beam-2Beam (BEAM) $ 0.020144
  • kucoin-sharesKuCoin (KCS) $ 10.40
  • axie-infinityAxie Infinity (AXS) $ 6.70
  • bitcoin-svBitcoin SV (BSV) $ 49.27
  • bittorrentBitTorrent (BTT) $ 0.000001
  • ordinalsORDI (ORDI) $ 45.50
  • zebec-protocolZebec Protocol (ZBC) $ 0.018580
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.65
  • dydx-chaindYdX (DYDX) $ 1.52
  • elrond-erd-2MultiversX (EGLD) $ 33.19
  • neoNEO (NEO) $ 12.70
  • chilizChiliz (CHZ) $ 0.100619
  • pendlePendle (PENDLE) $ 5.66
  • the-sandboxThe Sandbox (SAND) $ 0.382184
  • gnosisGnosis (GNO) $ 330.25
  • roninRonin (RON) $ 2.58
  • worldcoin-wldWorldcoin (WLD) $ 3.45
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,600.41
  • wormholeWormhole (W) $ 0.454517
  • akash-networkAkash Network (AKT) $ 3.34
  • tezosTezos (XTZ) $ 0.809783
  • oasis-networkOasis Network (ROSE) $ 0.118501
  • singularitynetSingularityNET (AGIX) $ 0.616588
  • msolMarinade Staked SOL (MSOL) $ 178.28
  • conflux-tokenConflux (CFX) $ 0.191053
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.92
  • nexoNEXO (NEXO) $ 1.34
  • livepeerLivepeer (LPT) $ 22.67
  • mina-protocolMina Protocol (MINA) $ 0.656679
  • usddUSDD (USDD) $ 0.999686
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.007250
  • havvenSynthetix Network (SNX) $ 2.19
  • ecasheCash (XEC) $ 0.000036
  • dexeDeXe (DEXE) $ 12.56
  • decentralandDecentraland (MANA) $ 0.384541
  • book-of-memeBOOK OF MEME (BOME) $ 0.010355
  • frax-etherFrax Ether (FRXETH) $ 3,593.04
  • fasttokenFasttoken (FTN) $ 2.21
  • lido-staked-solLido Staked SOL (STSOL) $ 176.11
  • safeSafe (SAFE) $ 1.59
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.52
  • aioz-networkAIOZ Network (AIOZ) $ 0.616467
  • apecoinApeCoin (APE) $ 1.07
  • klay-tokenKlaytn (KLAY) $ 0.179419
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,857.92
  • fraxFrax (FRAX) $ 0.998105
  • swethSwell Ethereum (SWETH) $ 3,798.86
  • iotaIOTA (IOTA) $ 0.190567
  • mantra-daoMANTRA (OM) $ 0.750757
  • kavaKava (KAVA) $ 0.557673
  • rocket-poolRocket Pool (RPL) $ 28.77
  • nervos-networkNervos Network (CKB) $ 0.013123
  • tether-goldTether Gold (XAUT) $ 2,333.14
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000104
  • heliumHelium (HNT) $ 3.42
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,909.11
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.109533
  • magaMAGA (TRUMP) $ 11.85
  • axelarAxelar (AXL) $ 0.780956
  • theta-fuelTheta Fuel (TFUEL) $ 0.081578
  • aevo-exchangeAevo (AEVO) $ 0.626272
  • 1inch1inch (1INCH) $ 0.420710
  • illuviumIlluvium (ILV) $ 79.72
  • blurBlur (BLUR) $ 0.309198
  • ioio.net (IO) $ 5.43
  • xdce-crowd-saleXDC Network (XDC) $ 0.034128
  • bitcoin-goldBitcoin Gold (BTG) $ 28.27
  • true-usdTrueUSD (TUSD) $ 0.998046
  • iotexIoTeX (IOTX) $ 0.050340
  • corgiaiCorgiAI (CORGIAI) $ 0.001370
  • woo-networkWOO (WOO) $ 0.248388
  • stader-ethxStader ETHx (ETHX) $ 3,703.76
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.11
  • ether-fiEther.fi (ETHFI) $ 4.02
  • raydiumRaydium (RAY) $ 1.74
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000022
  • astarAstar (ASTR) $ 0.078445
  • arkhamArkham (ARKM) $ 1.89
  • pax-goldPAX Gold (PAXG) $ 2,329.75
  • memecoin-2Memecoin (MEME) $ 0.021291
  • apenftAPENFT (NFT) $ 0.00000043
  • golemGolem (GLM) $ 0.427755
  • polymeshPolymesh (POLYX) $ 0.398826
  • aerodrome-financeAerodrome Finance (AERO) $ 0.850547
  • paypal-usdPayPal USD (PYUSD) $ 0.998273
  • manta-networkManta Network (MANTA) $ 1.28
  • curve-dao-tokenCurve DAO (CRV) $ 0.332777
  • stepnGMT (GMT) $ 0.193883
  • ocean-protocolOcean Protocol (OCEAN) $ 0.627366
  • dydxdYdX (ETHDYDX) $ 1.52
  • compound-ethercETH (CETH) $ 72.24
  • echelon-primeEchelon Prime (PRIME) $ 9.90
  • usdbUSDB (USDB) $ 0.999878
  • osmosisOsmosis (OSMO) $ 0.608269
  • kusamaKusama (KSM) $ 26.64
  • wemix-tokenWEMIX (WEMIX) $ 1.09
  • pepecoin-2PepeCoin (PEPECOIN) $ 3.31
  • biconomyBiconomy (BICO) $ 0.472119
  • mx-tokenMX (MX) $ 3.83
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.004266
  • safepalSafePal (SFP) $ 0.811958
  • aragonAragon (ANT) $ 9.21
  • compound-governance-tokenCompound (COMP) $ 53.79
  • radixRadix (XRD) $ 0.034857
  • zilliqaZilliqa (ZIL) $ 0.019693
  • holotokenHolo (HOT) $ 0.002052
  • superfarmSuperVerse (SUPER) $ 0.800476
  • dymensionDymension (DYM) $ 2.04
  • celoCelo (CELO) $ 0.665369
  • terra-luna-2Terra (LUNA) $ 0.518848
  • jito-governance-tokenJito (JTO) $ 2.89
  • ankrAnkr Network (ANKR) $ 0.034826
  • altlayerAltLayer (ALT) $ 0.229080
  • 0x0x Protocol (ZRX) $ 0.413600

ESET and Dutch police expose Ebury botnet’s cryptocurrency theft operations

0 22

ESET and Dutch police expose Ebury botnet’s cryptocurrency theft operations

  crypto.news 7 h

ESET and Dutch police expose Ebury botnet’s cryptocurrency theft operations

Dutch cybersecurity specialists have linked a major cryptocurrency theft to the infamous Ebury botnet, responsible for compromising over 400,000 servers over a 15-year period.

According to a report from Slovakian cybersecurity firm ESET, the incident was initially uncovered during a 2021 investigation by the Dutch National High Tech Crime Unit (NHTCU). During this investigation, operatives found the Ebury botnet on a server linked to crypto theft.

After this revelation, the Dutch crime unit collaborated with ESET, led by researcher Marc-Etienne Léveillé, who had been studying Ebury for over a decade.

Ebury operators allegedly used a sophisticated attack dubbed adversary-in-the-middle (AitM) to steal the crypto funds. The attack transpires with the botnet intercepting network traffic and capturing login credentials and session information.

“Cryptocurrency theft was not something that we’d ever seen them do before,” Léveillé noted.

The botnet redirects this traffic to servers controlled by the cybercriminals, allowing them to access and steal cryptocurrency from the wallets of the victims. In its report, ESET revealed that over 100,000 remained infected as of 2023.

Ebury specifically targets Bitcoin and Ethereum nodes, making off with wallets and other valuable credentials. The botnet would steal the funds once the unsuspecting victims entered their credentials on the infected server.

ESET and Dutch police expose Ebury botnet’s cryptocurrency theft operations

Flowchart of Ebury’s attack on crypto wallets | Source: welivesecurity

Further, once a victim’s system was compromised, Ebury would exfiltrate credentials and use them to infiltrate related systems. The report identified a wide array of victims ranging from universities, enterprises, internet service providers, and cryptocurrency traders.

The attackers also employ stolen identities to rent servers and deploy their attacks. As such, it is very difficult for law enforcement agencies to track down the identities of those behind this cybercrime racket.

“They’re really good at blurring the attribution,” Léveillé added.

You might also like: Crypto.com ‘disappointed’ over $3m fine by Dutch central bank, plans to appeal

One Ebury operator, Maxim Senakh, was arrested at the Finland-Russia border in 2015 and was extradited to the United States. The U.S. Department of Justice charged Senakh with computer fraud, to which he pleaded guilty in 2017. He was sentenced to four years behind bars.

While the masterminds behind Ebury remain at large, the NHTCU has revealed that several leads are being pursued.

Crypto thefts have become increasingly complicated over the years. Earlier this month, North Korean hackers employed a new malware variant dubbed “Durian” to targeted attacks on at least two cryptocurrency firms.

Prior to that, a January report from cybersecurity firm Kaspersky revealed that a malware was targetting cryptocurrency wallets on MacOS.

Read more: Kraken obtains Dutch license, expands crypto services in Europe

Source

Leave A Reply

Your email address will not be published.