Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Windigo

Description

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.(Citation: ESET Windigo Mar 2014)(Citation: CERN Windigo June 2019)

AI Analysis

· 2 weeks ago

Executive Summary

Windigo is a long‑running threat group that has compromised thousands of Linux and Unix servers since at least 2011. It leverages the Ebury SSH backdoor to build a large spam‑sending botnet and has continued to evolve the malware even after law‑enforcement takedowns of its original developers. The group primarily targets vulnerable SSH services on hosting providers and other internet‑facing infrastructure.

Goals & Targeting

Windigo’s strategic objective is financial gain through the operation of a large‑scale spam botnet. The group targets any internet‑facing Linux/Unix server with exposed SSH ports, with a particular focus on hosting providers, cloud instances, and poorly managed corporate servers. By compromising these systems, Windigo can leverage their bandwidth and IP reputation to send massive volumes of unsolicited email, often used for phishing, malware distribution, or advertising fraud. Typical victims are small‑to‑medium enterprises, academic institutions, and service providers that lack stringent SSH hardening practices, making them attractive for rapid credential‑spraying attacks.

Enhanced Description

The Windigo group emerged in the early 2010s, focusing on compromising Linux and Unix systems that expose SSH services to the internet. By deploying the custom Ebury backdoor, the actors gain persistent, low‑profile access to the compromised host, allowing them to install additional payloads, modify system binaries, and establish a relay for outbound spam traffic. Ebury is notable for its modular design, enabling the operators to update its capabilities remotely and to evade detection through techniques such as binary obfuscation and the use of legitimate system utilities for command execution. Law‑enforcement actions in 2014 and again in 2019 disrupted the original developers of Ebury, yet the operational infrastructure persisted. New variants of the backdoor continued to appear, suggesting that the original codebase was either handed over to other actors or that a broader community of cyber‑criminals adopted it. The continued updates through 2019 indicate a resilient supply chain and a business model centered on monetizing compromised servers through spam campaigns, and occasionally auxiliary activities such as cryptocurrency mining. Windigo’s tactics are typical of financially motivated cyber‑crime groups: automated SSH credential‑guessing, exploitation of weak or reused passwords, and the creation of cron‑based persistence mechanisms. Once a host is compromised, the group often installs additional tools for data exfiltration, proxying, and further lateral movement across the victim’s network. The group’s infrastructure relies heavily on bullet‑proof hosting providers and fast‑flux DNS to hide command‑and‑control (C2) endpoints. Although the public record on Windigo’s strategic objectives is limited, the group’s sustained focus on high‑volume spam distribution points to a clear profit‑driven motive. The lack of targeted espionage activity suggests that the primary goal is to maintain a reliable botnet for illicit revenue rather than to conduct nation‑state espionage.

Key Capabilities

  • Automated SSH credential brute‑forcing
  • Deployment and maintenance of the Ebury SSH backdoor
  • Persistence via cron jobs and systemd services
  • Use of legitimate system utilities for command execution (wget, curl, bash)
  • Outbound spam relay and bulk email distribution
  • Dynamic C2 communication over HTTP/HTTPS and DNS
  • Modular malware updates and evasion techniques

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Lateral Movement
Command and Control
Impact

ATT&CK Techniques

T1110.001
T1021.004
T1059.004
T1053.005
T1105
T1071.001
T1560.001
T1564.001

Software / Tooling

Ebury SSH backdoor
Hydra (SSH brute‑force tool)
Custom Linux RAT scripts
Cron / systemd for persistence
wget/curl for payload delivery
Bullet‑proof hosting services

Campaigns & Victims

Windigo’s campaigns are characterized by a steady, low‑noise operational tempo that emphasizes longevity over rapid, high‑profile attacks. The group typically initiates compromise through large‑scale password‑spraying against internet‑exposed SSH services, followed by rapid deployment of the Ebury backdoor. Once a foothold is secured, the actors configure cron‑based jobs to maintain persistence and to periodically pull updated modules from their C2 infrastructure. Spam campaigns originating from compromised hosts often exhibit rotating sender domains, fast‑flux DNS, and use of open relays to obscure the true source. Notable spikes in activity were observed in 2014 and 2017, coinciding with reported law‑enforcement actions, after which the group released updated Ebury variants to bypass emerging detection signatures.

IOC Patterns

  • Repeated SSH login failures from a single source IP followed by a successful login
  • Presence of the Ebury binary in /tmp, /usr/lib, or hidden directories with unusual file permissions
  • New cron entries or systemd timers that execute wget/curl commands to unknown URLs
  • Outbound SMTP traffic from previously non‑mail servers, often to known spam blacklists
  • C2 communication over HTTP/HTTPS to domains hosted on bullet‑proof hosting providers
  • Fast‑flux DNS records associated with command‑and‑control domains

Recommended Actions

  • Enforce SSH key‑based authentication and disable password logins where possible
  • Implement account lockout and rate‑limiting on SSH services
  • Monitor for anomalous outbound SMTP traffic from non‑mail servers
  • Regularly audit cron and systemd configurations for unauthorized jobs
  • Deploy endpoint detection rules that flag the Ebury binary hash and known file paths
  • Utilize threat‑intel feeds to block known C2 domains and IP ranges
  • Segment critical assets from internet‑facing servers to limit lateral movement
  • Patch OpenSSH and related libraries promptly

Suggested Tags

APT
spam botnet
Linux
SSH backdoor
Ebury
cybercrime
financially motivated

Confidence Assessment

The available data on Windigo is moderately confident, anchored by multiple security vendor reports and law‑enforcement disclosures spanning 2014‑2019. While the technical details of Ebury and the group's SSH‑based tactics are well documented, gaps remain regarding the current operational status post‑2019, specific geopolitical motivations, and any evolution toward newer payloads such as ransomware or cryptomining. Continuous monitoring and updated intel collection are recommended to fill these gaps.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET Windigo Mar 2014 — Bilodeau, O., Bureau, M., Calvet, J., Dorais-Joncas, A., Léveillé, M., Vanheuverzwijn, B. (2014, March 18). Operation Windigo – the vivisection of a large Linux server‑side credential‑stealing malware campaign. Retrieved February 10, 2021.
  2. CERN Windigo June 2019 — CERN. (2019, June 4). 2019/06/04 Advisory: Windigo attacks. Retrieved February 10, 2021.

Intel Summary

7

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Backdoor / C2
DDoS

Details

MITRE ID
G0124
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--4e868dad-682d-4897-b8df-2dc98f46c68a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.