[KB3508] The Windigo operation: How can I protect myself?

Issue

Details

Operation Windigo does not leverage any new vulnerabilities against Linux or Unix systems. Known systemic weaknesses were exploited by malicious actors to build and maintain the Windigo botnet.

See the figure below for a high-level perspective of the Windigo botnet:

Figure 1-1
Click the image to view larger in new window

 

Solution

ESET products detect and block the Linux/Ebury, Linux/Cdorked, Linux/Onimiki and Perl/Calfbot malware most commonly used by operation Windigo. We strongly recommend that you update your virus signature database regularly to maintain the highest level of security. ESET is currently working with law enforcement agencies and other Cybersecurity advocates to bring down the Windigo network.

 

What if I'm not an ESET Customer?

If you are not an ESET customer and want to make sure that you are not infected, you can choose to download a free trial version of ESET software, determine whether your system is infected or purchase ESET products.

 

What is Operation Windigo?

Operation Windigo is the name that Cybersecurity researchers have given a network of roughly 25,000 compromised Linux and Unix servers that redirect users around the world to malicious online content. For more information, visit the following ESET blog posts and read the ESET whitepaper available below:

Operation Windigo – the vivisection of a large Linux server-side credential-stealing malware campaign

Over 500,000 PCs attacked every day after 25,000 UNIX servers hijacked by Operation Windigo

Operation Windigo Whitepaper [PDF]

 

How to determine if my system is infected?

See Appendix 1: Indicators of Compromise in the ESET Operation Windigo whitepaper for a list of suspicious behaviors that can help you identify a compromised system.

Updated indicators are available on our GitHub page: https://github.com/eset/malware-ioc

 

Cleaning the malware variants

We advise anyone infected to completely wipe their servers and rebuild them from scratch using a verified source and reset all user and administrator credentials from known clean machines.

See the Appendix 2: Cleaning section in the whitepaper for more details

 

How can I protect my servers from operation Windigo?

Here are additional recommendations in order to protect yourself from this collection of threats:

  • Disable direct root login in your OpenSSH daemon
    (PermitRootLogin no in /etc/ssh/sshd_config)
  • Disable password-based logins and use an SSH key
  • Use SSH Agent Forwarding to SSH from servers to servers instead of copying your SSH private keys on servers
  • Use multi-factor authentication on your servers