Botnet Windigo 25.000 Unix servers for sending Spam and distributing malware

Security investigators from ESET, CERT-Bund and other companies have been tracking the criminal activity of a Botnet, which has infected more than 25.000 UNIX servers over the past two years. The botnet is called "Windigo" after the name of a mythical creature of American folklore.

malware

Infected servers were being used by criminals to send 35 million spam emails every day that managed to infect approximately 500.000 computers with malicious software.

“Every day over half a million computers were at risk ς, αφού επισκεπτόταν that contained malware planted by Windigo,” said its security researcher ESET Marc-Étienne Leveille.

Most of the infected servers are located on , τη Γερμανία, τη Γαλλία και το Ηνωμένο Βασίλειο. Πολλοί από αυτούς τους servers ανήκουν σε παροχείς υπηρεσιών φιλοξενίας. Ο κατάλογος των θυμάτων περιλαμβάνει εταιρείες όπως την and kernel.org.

As the Theregister.co.uk, ESET has been investigating the malicious campaign for about a year. It discovered a total of 25.000 servers that were infected, while over 10.000 are still.

Mac users were not ignored by cyber criminals. While Windows users were directed to malware websites, Mac users were targeting adult content or ads from dating sites.

Leveille highlights the fact that the backdoor Ebury developed by the intruders was not used to exploit vulnerabilities on Linux or OpenSSH but implanted it manually.

"The fact that they managed to do this on tens of thousands of different servers is creepy. "While anti-virus and two-factor authentication are common protection measures on computers we use at home, they are rarely used to protect servers, making them vulnerable to credential theft and easy installation of malware," he said.

If you are a Linux system administrator and want to control your system you can run the following command
$ ssh -G 2> & 1 | grep -e illegal -e unknown> / dev / null && echo “System clean” || echo “System infected”

The infected devices should be completely deleted and the operating system should be reinstalled.

Above information about Windigo is available at PDF of ESET.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).