LiveActive security incident?Get immediate response
MITRE ATT&CK® Reference

Groups

Intrusion-set and threat group profiles from official ATT&CK data.

1 records · validated library

Groups results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

GroupEnterprise

G0124: Windigo

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.[1][2]

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.