Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
7
techniques
1
software
9,976
corpus matches
profile
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.
techniques
7 attributed · most-instrumented first
software
1 malware & tools attributed
Ebury
S0377
read this carefully
9,976 corpus matches is not attribution
That count is indicators which exhibit techniques Windigo is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 9,976