Skip to main content

Unix botnet Operation Windigo steals your credentials and sends tons of spam

botnet
Image used with permission by copyright holder

A security research team has discovered a long-standing Unix botnet which has generated a massive amount of malware in recent years. Dubbed “Operation Windigo,” the botnet was discovered and reported by antivirus software-maker ESET, working with an international task force consisting of the German Computer Emergency Response Team, or CERT-BUND, and the Swedish National Infrastructure for Computing, among others. As malware goes, Windigo operates a bit like a Swiss Army knife, doing everything from redirecting traffic to compromised sites, to sending millions of spam emails every day for at least two and a half years.

According to ESERT, Windigo allegedly hijacked 25,000 UNIX servers using a Trojan, stealing credentials and data from its targets. ESET Security Researcher Marc-Étienne Léveillé says that Windigo attacks more than 500,000 targets per day.

WINDIGO_SM_Picture
Image used with permission by copyright holder

To make matters worse, Windigo takes different forms depending on what OS you’re using. When Windigo attacks Windows PCs, they attempt to swipe the target’s data using an exploit kit, while Mac users get hit with popups for dating sites.

How to Check if Your Server is Infected by the Operation Windigo Botnet

There’s a way to fight back though. ESET says that Unix system admins can identify whether or not a their server is infected by Windigo by using the command below.

$ ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo “System clean” || echo “System infected”

If the system is infected, ESET recommends you wipe the machine, re-install the OS, and change all of the passwords used with that system.

“We realise that wiping your server and starting again from scratch is tough medicine,” says Léveillé, “but if hackers have stolen or cracked your administrator credentials and had remote access to your servers, you cannot take any risks.”

Editors' Recommendations

Topics
Mike Epstein
Former Digital Trends Contributor
Michael is a New York-based tech and culture reporter, and a graduate of Northwestwern University’s Medill School of…
4 CPUs you should buy instead of the Ryzen 7 7800X3D
AMD Ryzen 7 7800X3D sitting on a motherboard.

The Ryzen 7 7800X3D is one of the best gaming processors you can buy, and it's easy to see why. It's easily the fastest gaming CPU on the market, it's reasonably priced, and it's available on a platform that AMD says it will support for several years. But it's not the right chip for everyone.

Although the Ryzen 7 7800X3D ticks all the right boxes, there are several alternatives available. Some are cheaper while still offering great performance, while others are more powerful in applications outside of gaming. The Ryzen 7 7800X3D is a great CPU, but if you want to do a little more shopping, these are the other processors you should consider.
AMD Ryzen 7 5800X3D

Read more
Even the new mid-tier Snapdragon X Plus beats Apple’s M3
A photo of the Snapdragon X Plus CPU in the die

You might have already heard of the Snapdragon X Elite, the upcoming chips from Qualcomm that everyone's excited about. They're not out yet, but Qualcomm is already announcing another configuration to live alongside it: the Snapdragon X Plus.

The Snapdragon X Plus is pretty similar to the flagship Snapdragon X Elite in terms of everyday performance but, as a new chip tier, aims to bring AI capabilities to a wider portfolio of ARM-powered laptops. To be clear, though, this one is a step down from the flagship Snapdragon X Elite, in the same way that an Intel Core Ultra 7 is a step down from Core Ultra 9.

Read more
Gigabyte just confirmed AMD’s Ryzen 9000 CPUs
Pads on the AMD Ryzen 7 7800X3D.

Gigabyte spoiled AMD's surprise a bit by confirming the company's next-gen CPUs. In a press release announcing a new BIOS for X670, B650, and A620 motherboards, Gigabyte not only confirmed that support has been added for next-gen AMD CPUs, but specifically referred to them as "AMD Ryzen 9000 series processors."

We've already seen MSI and Asus add support for next-gen AMD CPUs through BIOS updates, but neither of them called the CPUs Ryzen 9000. They didn't put out a dedicated press release for the updates, either. It should go without saying, but we don't often see a press release for new BIOS versions, suggesting Gigabyte wanted to make a splash with its support.

Read more