logo

operation_windigo.pdf

ID: c894b4c3-926e-4227-aab7-f4f36ef1a1e2

STIX ID: report--c894b4c3-926e-4227-aab7-f4f36ef1a1e2

Threat Score

80/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
Operation Windigo is a long-running, large-scale criminal campaign that has compromised Linux/Unix servers worldwide (tens of thousands of hosts) to operate a multifunctional botnet: an OpenSSH backdoor (Linux/Ebury) that steals SSH credentials and provides persistent root access, an HTTP redirection backdoor (Linux/Cdorked) combined with a DNS backdoor (Linux/Onimiki) that funnels visitors to exploit kits, and a Perl-based spam module (Perl/Calfbot); the report includes technical internals, DGAs, shared-memory exfiltration methods, IOCs and cleaning/prevention guidance.