CDorked is a Linux server-side backdoor associated with Operation Windigo and closely linked to the broader Ebury malware ecosystem. It compromises web server software by trojanizing HTTP daemon binaries, including Apache httpd, nginx, and lighttpd, turning legitimate web servers into covert malicious infrastructure while preserving normal service for most visitors. The malware is known for selectively manipulating HTTP traffic and includes logic that can redirect specially crafted requests, a behavior historically used as a simple infection check. Detection guidance has also described command-and-control or configuration activity conveyed through distinctive HTTP cookie and URL patterns.
CDorked is part of a cluster of interrelated Linux malware families that includes Ebury, Calfbot, and Onimiki. Within that ecosystem, compromised servers were used for malicious traffic redirection, malware distribution, spam operations, and in some cases theft from compromised e-commerce environments. CDorked stands out as the web-tier component of the operation, embedding itself directly into internet-facing web services to provide stealthy post-compromise control and traffic manipulation on Linux servers.
The malware targets Linux-based web infrastructure and is notable for long-term, covert abuse of legitimate server processes rather than noisy destructive activity. Public reporting ties it to activity dating back to at least the early 2010s, with analyses highlighting multiple versions and evolving detection characteristics over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar HTTPD-infecting backdoor using shared memory, but the article states the observed malware is not an evolution of Cdorked.
A Linux malware component associated with Operation Windigo; the content provides an IOC involving a request to favicon.iso redirecting to Google.com.
A named malware/tool associated with the Windigo IoC set via detection rules.
Linux web server backdoor associated with Operation Windigo that manipulates HTTP traffic and can redirect requests, with configuration commands detectable via network rules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.