Windigo compromises Linux and Unix servers using the Ebury SSH backdoor to build spam botnets.
Analyst brief
The Windigo group has been active since at least 2011, compromising Linux and Unix servers using the Ebury SSH backdoor. It primarily targets server infrastructure to build spam botnets and steal credentials. Key TTPs include Drive-by Compromise for initial access, Command and Scripting Interpreter for execution, and Data from Local System for collection; Ebury malware is used to backdoor SSH and maintain persistence with Proxy for C2. Defenders should monitor SSH daemons for unauthorized modifications, inspect shared memory for hidden backdoors, and enforce strict credential hygiene.
Windigo
unknown
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.