Windigo
MITRE ATT&CK: G0124 View on attack.mitre.org
Aliases: Windigo
- First seen
- 2011-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:30:44
Targeted industries: technology-and-telecommunications media-and-entertainment
Context
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.
Detection coverage
- 1 YARA rules
- 167 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Software Discovery (attack-pattern)
- Proxy (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Ebury (malware)
Reports & references
- MITRE ATT&CK — G0124 (report)
- security.web.cern.ch — Windigo.Shtml (report)
- ESET — Operation Windigo The Vivisection Of A Large Linux Server Side Credential Stealing Malware Campaign (report)