NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Windigo

Windigo

Overview

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.

TTPs — 7 techniques across 5 tactics

Initial Access

Collection

Command and Control

Tools & malware (1)

Ebury

Reporting (2)