Windigo

MITRE
Tipo:
Unknown
Paese:
Unknown
Prima attivita:
Unknown
Dettagli:

The [Windigo](https://attack.mitre.org/groups/G0124) group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the [Ebury](https://attack.mitre.org/software/S0377) SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, [Windigo](https://attack.mitre.org/groups/G0124) operators continued updating [Ebury](https://attack.mitre.org/software/S0377) through 2019.(Citation: ESET Windigo Mar 2014)(Citation: CERN Windigo June 2019)

MITRE ATT&CK: View on MITRE
Tecniche Utilizzate (7)
ID ATT&CK Tattiche
T1005 Data from Local System -
T1059 Command and Scripting Interpreter -
T1082 System Information Discovery -
T1083 File and Directory Discovery -
T1090 Proxy -
T1189 Drive-by Compromise -
T1518 Software Discovery -
Malware Utilizzato (1)
Metadata
ID: 907
Created: 13/01/2026 17:48
Updated: 06/03/2026 04:00