Operation Windigo: 10,000 infected Linux servers redirecting half a million visitors to malware every day
Security firm ESET today published a technical analysis on Linux/Ebury, an OpenSSH backdoor and credential stealer the company discovered last month. Over the last few weeks, thousands of victims have been notified that their servers were infected, and the details being released today are in an effort to raise further awareness. Dubbed Operation Windigo, the scheme runs on an infrastructure entirely hosted on compromised computers: 25,000 Linux servers in total over the last two years, with over 10,000 still infected today. The number is significant, as ESET points out, if you remember each of these systems has access to significant…
This story continues at The Next Web




