Calfbot is a Perl-based spam bot associated with the broader Operation Windigo malware ecosystem, alongside components such as Ebury and Cdorked. It has been observed on compromised Linux server infrastructure used by the Windigo operators for large-scale abuse activities including spam operations. Within that ecosystem, Calfbot functioned as a server-side malware component rather than an endpoint threat, contributing to monetization of compromised hosts.
Available reporting supports that Calfbot communicates over HTTPS and can also be identified through characteristic DNS request patterns, indicating network-enabled command or coordination behavior with an emphasis on evading simple protocol-based detection. It is consistently described as a spam bot, which supports classification as a botnet-oriented malware family used to automate abusive messaging activity from infected systems.
Calfbot is tied to Linux-focused intrusions connected to long-running Windigo activity dating back to at least the early 2010s. The broader operation targeted internet-facing servers and used multiple malware families for credential theft, web server compromise, traffic redirection, and spam distribution. In that context, Calfbot appears to have been one of the operational components deployed on compromised infrastructure to support spam delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware component named as part of the broader Windigo-related toolset affecting Linux servers.
A named malware/tool associated with the Windigo IoC set via detection rules.
Perl-based malware associated with Operation Windigo that communicates over HTTPS and uses specific DNS requests/domains for command-and-control or beaconing.
Perl-based spam bot that uses generated domains and is included as a related component of the Windigo/Ebury operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.