operation_windigo.pdf
ID: c894b4c3-926e-4227-aab7-f4f36ef1a1e2
STIX ID: report--c894b4c3-926e-4227-aab7-f4f36ef1a1e2
Threat Score
80/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
Operation Windigo is a long-running, large-scale criminal campaign that has compromised Linux/Unix servers worldwide (tens of thousands of hosts) to operate a multifunctional botnet: an OpenSSH backdoor (Linux/Ebury) that steals SSH credentials and provides persistent root access, an HTTP redirection backdoor (Linux/Cdorked) combined with a DNS backdoor (Linux/Onimiki) that funnels visitors to exploit kits, and a Perl-based spam module (Perl/Calfbot); the report includes technical internals, DGAs, shared-memory exfiltration methods, IOCs and cleaning/prevention guidance.
