Windigo
The [Windigo](https://attack.mitre.org/groups/G0124) group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the [Ebury](https://attack.mitre.org/software/S0377) SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, [Windigo](https://attack.mitre.org/groups/G0124) operators continued updating [Ebury](https://attack.mitre.org/software/S0377) through 2019.(Citation: ESET Windigo Mar 2014)(Citation: CERN Windigo June 2019)
Properties
- stix_id
- intrusion-set--4e868dad-682d-4897-b8df-2dc98f46c68a
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (7)
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of intera
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file s
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may u
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and
Software & Tools (1)
[Ebury](https://attack.mitre.org/software/S0377) is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed b
Explore this actor's full graph with Ninja Signal