AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Windigo
Aliases: None listed
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Blue Team & Defensive Security · explicit-idEvidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · topic-matchTimeline reconstruction, ATT CK mapping, CTI, and confidence
Digital Forensics & Incident Response (DFIR) · topic-matchEndpoint live response and volatile acquisition
Digital Forensics & Incident Response (DFIR) · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchAI-assisted OSINT with bounded tools, citations, and human review
OSINT & Reconnaissance · topic-matchScripts, documents, shortcuts, and fileless chains
Malware Analysis & Reverse Engineering · topic-matchTraining data, ingestion, retrieval, RAG, and knowledge integrity
AI Security · topic-matchAgents, tools, plugins, browsers, and MCP security
AI Security · topic-matchIdentity, authorization, tenancy, and human approval
AI Security · topic-matchAI red teaming, evaluation, and reproducible security testing
AI Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-match