- Target Sectors
- Hosting Providers, Web Hosting, Unspecified
- Associated Malware
- Ebury, CDorked, Calfbot, Win32/Glubteta.M, Linux/Onimiki
Overview
Windigo, tracked as G0124, is a highly sophisticated and persistent threat group that has been actively compromising Linux and Unix servers since at least 2011, though their core Ebury malware first appeared in 2009. The group’s primary objective has consistently been financial gain, achieved by leveraging a vast botnet built from infected servers for activities such as spam distribution, web traffic redirection, credential theft, and more recently, cryptocurrency and credit card exfiltration.
Operation Windigo, as detailed in a 2014 ESET report, initially brought the group into public awareness, exposing their compromise of over 25,000 servers globally. Despite a significant law enforcement intervention in 2015 that led to an arrest, Windigo operators have demonstrated remarkable resilience and adaptability. They have continually updated their primary malware, Ebury, with new functionalities and evasive techniques, maintaining a substantial network of compromised systems. As of late 2023, over 100,000 servers remained compromised, and Ebury saw its latest update (version 1.8.2) in January 2024, indicating ongoing and active operations. The group’s name, Windigo, reportedly draws from North American folklore, referencing a malevolent, insatiably hungry entity, a fitting metaphor for their relentless and expansive operations.
Tactics & Techniques
Windigo’s operational methodology centers on compromising Linux and Unix servers, typically exploiting known systemic weaknesses rather than zero-day vulnerabilities. Their preferred method for establishing persistence is through the Ebury SSH backdoor. This backdoor is cunningly injected by modifying legitimate shared libraries (e.g., libkeyutils.so) or utilizing LD_PRELOAD, allowing it to alter the behavior of OpenSSH client and server programs.
Once a server is compromised, Windigo employs a range of techniques for information gathering and credential theft. Ebury is designed to intercept unencrypted private keys and pass-phrases, and it exfiltrates lists of outbound and inbound SSH sessions by monitoring known_host files and wtmp records. The group also uses Perl scripts to gather system information, such as installed software and Linux distribution details.
For command and control (C2), Ebury communicates with its operators using custom DNS queries or the Xcat command to send stolen credentials. A notable feature is Ebury’s sophisticated Domain Generation Algorithm (DGA) fallback mechanism, which is activated if a direct connection to the infected system isn’t made for three days, ensuring continued data exfiltration. C2 traffic is encrypted using the client’s IP address and then encoded as a hexadecimal string, enhancing stealth.
Windigo exhibits advanced defense evasion capabilities. Ebury functions as a userland rootkit, employing self-hiding techniques that make its files and operational resources, like processes and sockets, invisible to standard system inspections. They have also incorporated modified Netfilter tools to inject and conceal firewall rules, further hindering detection. Recent updates to Ebury include injecting OpenSSH server configurations directly into memory by parsing the sshd binary, and a hardened backdoor mechanism that now requires a private key for authentication, making unauthorized access more difficult even if the backdoor is discovered.
The impact of Windigo’s operations is multifaceted and financially driven. At its peak, the botnet was responsible for sending approximately 35 million spam messages and redirecting 500,000 web users daily to malicious content, including exploit kits. Beyond spam and redirection, the group distributes other malware, such as the Win32/Glubteta.M Windows proxy via drive-by downloads. More recently, their activities have diversified to include proxying traffic, conducting Adversary-in-the-Middle (AitM) attacks, and direct theft of cryptocurrency wallets and credit card details, underscoring their evolving monetization strategies.
Notable Campaigns
The definitive “Operation Windigo” campaign was publicly exposed by ESET in March 2014, detailing the widespread compromise of over 25,000 Linux and Unix servers. This extensive operation revealed the core components of the Windigo threat, particularly the pervasive use of the Ebury SSH backdoor. High-profile organizations such as cPanel, a popular web hosting control panel, and kernel.org, the main repository for the Linux kernel source code, were identified among the victims.
A significant event in Windigo’s history was the arrest of a perpetrator at the Finland-Russia border in 2015, who was later extradited to the United States and pleaded guilty in 2017. While this law enforcement action did temporarily disrupt some of the group’s monetization activities, it failed to dismantle the entire botnet. The Windigo operators adapted quickly, continuing to develop and update their malware, demonstrating their resilience and commitment to their criminal enterprise.
Associated Malware & Tools
Windigo relies on a suite of interconnected malware and tools to maintain its botnet and achieve its objectives. The central piece of their arsenal is:
- Ebury (S0377): An OpenSSH backdoor and credential stealer, considered the core of the Windigo operation. It functions as a userland rootkit, designed for stealth and persistence.
- CDorked: This component is specifically designed for web traffic redirection, a key monetization tactic for the group.
- Calfbot (Perl/Calfbot): Primarily used for operating the spam botnet, responsible for the massive volumes of unsolicited emails sent from compromised servers.
- Win32/Glubteta.M: A generic Windows proxy malware that Windigo distributes via drive-by downloads, expanding their reach to end-user machines.
- Linux/Onimiki: Mentioned in ESET’s documentation as another malware variant associated with Operation Windigo.
Beyond these primary malware families, Windigo has expanded its toolkit to include more specialized components. This includes custom Apache modules designed to exfiltrate HTTP requests or proxy traffic, as well as Linux kernel modules tailored to perform sophisticated traffic redirections. They also employ modified Netfilter tools to inject and conceal firewall rules, further enhancing their ability to evade detection and maintain control over compromised systems. Perl scripts are frequently utilized for reconnaissance and information gathering on targeted servers.
Current Status
Windigo remains an active and evolving threat. Contrary to the common fate of many threat groups following law enforcement action, Windigo has not been disbanded and continues its operations with considerable scale. The Ebury botnet, which forms the backbone of their operations, is still alive and continues to grow. ESET Research, a long-standing authority on Windigo, confirmed in May 2024 that the botnet is active and has diversified its monetization efforts.
The most recent update to the Ebury backdoor, version 1.8.2, was observed in January 2024, demonstrating the group’s ongoing development and maintenance efforts. As of late 2023, the group still controlled over 100,000 compromised servers, a testament to their sustained presence and operational capacity. Between February 2022 and May 2023, Windigo was observed conducting Adversary-in-the-Middle (AitM) attacks against more than 200 targets across over 75 networks in 34 different countries, highlighting their continued global reach and adaptability in exploiting compromised infrastructure for financial gain. The group’s ability to compromise hosting provider infrastructure, leading to the infection of tens of thousands of customer-rented servers, underscores the significant and ongoing risk they pose to a wide range of organizations.
Related content
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call