NEW: Group Profiler — instant APT intel lookup. Try it →

Windigo

Overview

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.

Naming & attribution

Windigo is tracked under 1 names across the industry. It uses 7 documented ATT&CK techniques — more than 20% of the 174 groups tracked here. Activity attributed since at least 2011.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Dark Caracal — 3 shared techniques (19% overlap)
  • Inception Russia — 4 shared techniques (16% overlap)
  • Stealth Falcon — 3 shared techniques (15% overlap)
  • APT37 North Korea — 4 shared techniques (13% overlap)
  • Winter Vivern Russia — 4 shared techniques (13% overlap)
  • CURIUM Iran — 3 shared techniques (13% overlap)

Malware families with current indicators

One family attributed to Windigo, carrying 15 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Ebury 15 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 7 techniques across 5 tactics

Initial Access

Collection

Command and Control

Tools & malware (1)

Ebury

Reporting (2)