Windigo

MITRE ATT&CK: G0124 View on attack.mitre.org

Aliases: Windigo

First seen
2011-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:30:44

Targeted industries: technology-and-telecommunications media-and-entertainment

Context

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.

Detection coverage

  • 1 YARA rules
  • 167 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Software Discovery (attack-pattern)
  • Proxy (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Ebury (malware)

Reports & references

  • MITRE ATT&CK — G0124 (report)
  • security.web.cern.ch — Windigo.Shtml (report)
  • ESET — Operation Windigo The Vivisection Of A Large Linux Server Side Credential Stealing Malware Campaign (report)

External references