Onimiki is a Linux DNS server backdoor associated with the Operation Windigo malware ecosystem. It is designed to compromise systems running the BIND name server by trojanizing the named service, allowing an attacker to abuse a legitimate DNS server as a covert access mechanism. Reported infections were observed on hosts already operating active BIND infrastructure and serving legitimate DNS traffic, which provides cover for malicious communications.
Within the broader Windigo cluster, Onimiki is grouped with other server-side malware families including Ebury, Cdorked, and Calfbot. Its role is distinct from web-server and SSH-focused components in that it targets DNS infrastructure specifically. Detection guidance for Onimiki has focused on anomalous inbound or outbound DNS requests matching patterns associated with the malware's backdoor communications.
Onimiki targets Linux systems running BIND and functions as a persistent server-side backdoor embedded into a core network service. This makes it relevant to organizations operating internet-facing DNS infrastructure, hosting providers, and other environments where compromised authoritative or recursive DNS servers could provide durable attacker access and concealment within normal service activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DNS server backdoor for Linux, described here as trojanizing BIND/named and linked to the Windigo/Ebury operation.
DNS server backdoor associated with Operation Windigo that infects BIND/named installations and leaves limited evidence beyond a modified binary.
A named malware/tool associated with the Windigo IoC set via detection rules.
A DNS server backdoor that trojanizes BIND named binaries on already active DNS servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.