Windigo

G0124

Threat group.View on attack.mitre.org

About this group

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1005
Data from Local System

Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.

T1059
Command and Scripting Interpreter

Windigo has used a Perl script for information gathering.

T1082
System Information Discovery

Windigo has used a script to detect which Linux distribution and version is currently installed on the system.

T1083
File and Directory Discovery

Windigo has used a script to check for the presence of files created by OpenSSH backdoors.

T1090
Proxy

Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure.

T1189
Drive-by Compromise

Windigo has distributed Windows malware via drive-by downloads.

T1518
Software Discovery

Windigo has used a script to detect installed software on targeted systems.

Software1

Campaigns0

None recorded.

References2

  1. CERN Windigo June 2019 Open source
    CERN. (2019, June 4). 2019/06/04 Advisory: Windigo attacks. Retrieved February 10, 2021.
  2. ESET Windigo Mar 2014 Open source
    Bilodeau, O., Bureau, M., Calvet, J., Dorais-Joncas, A., Léveillé, M., Vanheuverzwijn, B. (2014, March 18). Operation Windigo – the vivisection of a large Linux server‑side credential‑stealing malware campaign. Retrieved February 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.