Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors. |
| T1059 Command and Scripting Interpreter |
Windigo has used a Perl script for information gathering. |
| T1082 System Information Discovery |
Windigo has used a script to detect which Linux distribution and version is currently installed on the system. |
| T1083 File and Directory Discovery |
Windigo has used a script to check for the presence of files created by OpenSSH backdoors. |
| T1090 Proxy |
Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure. |
| T1189 Drive-by Compromise |
Windigo has distributed Windows malware via drive-by downloads. |
| T1518 Software Discovery |
Windigo has used a script to detect installed software on targeted systems. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.