Windigo is a long-running Linux server compromise operation and malware cluster centered on the Ebury backdoor, with related components including CDorked, Calfbot, Onimiki, and Helimod. Activity associated with the operation dates back to at least 2011 and has been linked to the compromise of thousands of Linux servers. The operation is notable for turning high-uptime internet-facing servers into criminal infrastructure used for spam distribution, malware delivery, web traffic redirection, and, in some cases, theft of payment-card data from compromised e-commerce environments.
Ebury is the best-known malware component associated with Windigo and functions as an OpenSSH backdoor targeting Linux systems. It provides persistent unauthorized access to compromised servers and supports broader post-compromise abuse. Other components tied to the operation have included CDorked, a malicious web server component used to manipulate web traffic, and Calfbot, which has been associated with spam operations. Public detection content also associates Onimiki and Helimod with the broader Windigo ecosystem.
Windigo primarily targets Linux servers rather than end-user systems. The operation has focused on compromising exposed server infrastructure and maintaining long-term access on valuable hosts. Reported abuse of infected systems includes use as system backdoors, spam relays, malware distribution nodes, and compromised web servers involved in monetization schemes. Cleanup has historically been described as complex because multiple malicious components may coexist on the same host and operators have adapted their tooling over time.
The available information supports Windigo as a Linux-focused backdoor-centric malware operation with persistence and post-exploitation functionality. Specific initial access vectors are not established here at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download"; "ADVSTORESHELL can run Systeminfo to gather information about the victim."; "Kimsuky has enumerated drives, OS type, OS version, and other information using a script or the 'systeminfo' command."
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a threat annotation associated with Linux post-exploitation/persistence behavior involving binaries executed from shared memory directories.
A Linux server compromise operation tied to multiple malware components used to infect servers and misuse them for malware distribution, spam, and theft of credit card data from compromised e-commerce web servers.
The content indicates a GitHub repository section dedicated to IOC data for Windigo, implying Windigo is the malware/investigation subject. No behavioral or functional description is provided in the visible content.
Windigo appears to be the primary malware/campaign entry referenced in this repository listing, with associated components/tools such as Ebury, Cdorked, and Onimiki indicated by filenames.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.