Skip to main content

Unix botnet Operation Windigo steals your credentials and sends tons of spam

A security research team has discovered a long-standing Unix botnet which has generated a massive amount of malware in recent years. Dubbed “Operation Windigo,” the botnet was discovered and reported by antivirus software-maker ESET, working with an international task force consisting of the German Computer Emergency Response Team, or CERT-BUND, and the Swedish National Infrastructure for Computing, among others. As malware goes, Windigo operates a bit like a Swiss Army knife, doing everything from redirecting traffic to compromised sites, to sending millions of spam emails every day for at least two and a half years.

According to ESERT, Windigo allegedly hijacked 25,000 UNIX servers using a Trojan, stealing credentials and data from its targets. ESET Security Researcher Marc-Étienne Léveillé says that Windigo attacks more than 500,000 targets per day.

WINDIGO_SM_Picture
Image used with permission by copyright holder

To make matters worse, Windigo takes different forms depending on what OS you’re using. When Windigo attacks Windows PCs, they attempt to swipe the target’s data using an exploit kit, while Mac users get hit with popups for dating sites.

Recommended Videos

How to Check if Your Server is Infected by the Operation Windigo Botnet

There’s a way to fight back though. ESET says that Unix system admins can identify whether or not a their server is infected by Windigo by using the command below.

$ ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo “System clean” || echo “System infected”

If the system is infected, ESET recommends you wipe the machine, re-install the OS, and change all of the passwords used with that system.

“We realise that wiping your server and starting again from scratch is tough medicine,” says Léveillé, “but if hackers have stolen or cracked your administrator credentials and had remote access to your servers, you cannot take any risks.”

Mike Epstein
Associate Editor, Gaming
Michael is a New York-based tech and culture reporter, and a graduate of Northwestwern University’s Medill School of…
Topics
AMD’s RDNA 4 may surprise us in more ways than one
AMD RX 7800 XT and RX 7700 XT graphics cards.

Thanks to all the leaks, I thought I knew what to expect with AMD's upcoming RDNA 4. It turns out I may have been wrong on more than one account.

The latest leaks reveal that AMD's upcoming best graphics card may not be called the RX 8800 XT, as most leakers predicted, but will instead be referred to as the  RX 9070 XT. In addition, the first leaked benchmark of the GPU gives us a glimpse into the kind of performance we can expect, which could turn out to be a bit of a letdown.

Read more
This futuristic mechanical keyboard will set you back an eye-watering $1,600
Hands typing on The Icebreaker keyboard.

I've complained plenty about how some of the best gaming keyboards are too expensive, from the Razer Black Widow V4 75% to the Wooting 80HE, but nothing comes remotely close to The Icebreaker. Announced nearly a year ago by Serene Industries, The Icebreaker is unlike any keyboard I've ever seen -- and it's priced accordingly at $1,600. Plus shipping, of course.

What could justify such an extravagant price? Aluminum, it turns out. The keyboard is constructed of one single block of 6061 aluminum in what Serene Industries calls an "unorthodox wedge form." As if that wasn't enough metal, the keycaps are also made of aluminum, and Serene says they include "about 800" micro-perforations that allow the LED backlight of the keyboard to shine through.

Read more
Google one-ups Microsoft by making chats easier to transfer
Google Spaces in Google Chat on a MacBook.

In a recent blog post, Google announced that it is making it easier for admins to migrate from Microsoft Teams to Google Chat to reduce downtime. Admins can easily do this within the Google Chat migration menu and connect to opposing Microsoft accounts to transfer Teams data.

Google gave step-by-step instructions for admins on how to transfer the messages. Admins need to connect to their Microsoft account and upload a CSV of the Teams from where they transfer the messages. From there, it requires just entering a starting date for messages to be migrated from Teams and clicking Star migration. Once it's complete, it'll make the migrated space, messages, and conversation data available to Google Workspace users.

Read more