Windigo
Overview
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.
Naming & attribution
Windigo is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2011.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Dark Caracal — 3 shared techniques (19% overlap)
- Inception Russia — 4 shared techniques (16% overlap)
- Stealth Falcon — 3 shared techniques (15% overlap)
- APT37 North Korea — 4 shared techniques (13% overlap)
- Winter Vivern Russia — 4 shared techniques (13% overlap)
- CURIUM Iran — 3 shared techniques (13% overlap)
Malware families with current indicators
One family attributed to Windigo, carrying 15 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Ebury 15 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 7 techniques across 5 tactics
Initial Access
-
T1189Drive-by Compromise
Execution
Discovery
-
T1082System Information Discovery -
T1083File and Directory Discovery -
T1518Software Discovery
Collection
-
T1005Data from Local System
Command and Control
-
T1090Proxy
Tools & malware (1)
Ebury
Reporting (2)
- 2019/06/04 Advisory: Windigo attacks — CERN
- Operation Windigo – the vivisection of a large Linux server‑side credential‑stealing malware campaign — Bilodeau, O., Bureau, M., Calvet, J., Dorais-Joncas, A., Léveillé, M., Vanheuverzwijn, B