Winnti is a backdoor malware family with Windows and Linux variants, used by multiple China-linked threat actors for covert access and data theft. Publicly characterized in 2013, it is closely associated with the Winnti Group and APT41 ecosystem, and has also been used by Earth Lusca and TeleBoyi. Its deployment spans gaming, telecommunications, pharmaceuticals, and technology organizations. Winnti supported early attacks against South Korean gaming companies, and a Linux variant was identified on systems belonging to the German pharmaceutical company Bayer.
Windows deployments can comprise an installer, a loader, and the backdoor payload. Execution techniques include DLL search-order hijacking, DLL side-loading through legitimate applications, and signed binary proxy execution using Rundll32. An analyzed variant manually maps its DLL into memory and erases its PE headers to impede detection and analysis. The family also uses rootkit components to conceal activity.
Certain Windows variants include a driver component known as NdisReroute, which recognizes an initial TCP handshake and redirects traffic from ports already occupied by legitimate applications to the malware's user-space component. This allows covert communications through existing network services. An analyzed Winnti variant incorporates the open-source iodine implementation for DNS tunneling, using encoded subdomains to carry command-and-control traffic. These mechanisms support concealed remote access and the theft of data and files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
[16] The rush for CVE-2013-3906 - a hot commodity ... [17] Exploit Proliferation: Additional Threat Groups Acquire CVE-2013-3906
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"At the second victim, we observed a loader that is highly similar to previous Winnti v.4 malware loaders" used to decrypt and execute a payload.
The 2016 attack on TeamViewer, in which the hackers breached their network using Winnti (backdoor), was also believed to be linked with this group.
Earth Lusca [is] known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families.
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
31 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 exploits vulnerabilities in public-facing applications and deploys malware such as Winnti and ShadowPad to maintain persistence.
The group has since earned infamy for being involved in malicious activities associated with targeted attacks, such as deploying spear-phishing campaigns and building a backdoor.
The library used to hide Winnti’s system activity is a copy of the open-source userland rootkit Azazel, with minor changes. When executed, it will register symbols for multiple commonly used functions, including: open(), rmdir(), and unlink(), and modify their returns to hide the malware’s operations.
In some instances, Winnti operators wrote the names of their targets directly into the malware, obfuscated with a rolling XOR cipher.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
Kaspersky researchers uncovered that the digital signature used to sign the original Winnti malware was stolen from another video game vendor known as KOG... the Winnti group had used at least 18 stolen code-signing certificates in its campaigns
Inside the cloud network, the implant supports lateral movement by periodically sending UDP broadcast beacons to 255.255.255.255 on port 6006, allowing other compromised hosts to discover each other and share tasking without extra direct C2 traffic.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
a feature of recent versions of Winnti we came across in the Linux variant (as well as Windows) that allows the operators to initiate a connection directly to an infected host, without requiring a connection to a control server. This secondary communication channel may be used by operators when access to the hard-coded control servers is disrupted.
For years, TAU has reversed and emulated the network Command and Control (C2) protocols of high-profile malware families... Continuing its research, TAU has discovered additional Winnti 4.0 C2 servers actively used over the last two years.
According to the Breakglass Intelligence report, the backdoor uses an unusual but effective command-and-control strategy built around SMTP traffic over port 25, rather than more common HTTPS-based channels. This choice allows the implant to disguise its C2 as email traffic... All collected secrets are encrypted using a hardcoded AES-256 key and staged locally prior to exfiltration through the SMTP-based C2 channel.
prior reporting suggests that the operators commonly deploy plugins for remote command execution, file exfiltration, and socks5 proxying on the infected host.
The driver component of Winnti (aka "NdisReroute") is able to reroute network traffic from ports that are already occupied by legit applications to the malware's userspace component. The first packet of a TCP stream signals the driver that the stream shall be rerouted.
References include 'Attacks on East Asia using Google Code for Command and Control' and 'Winnti Abuses GitHub for C&C Communications.'
This component is primarily designed to handle communications and the deployment of modules directly from the command-and-control servers.
772 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named backdoor mentioned solely as malware used in a historical 2016 breach of TeamViewer's corporate network.
A malware family mentioned as part of ESET's attribution linkage for SparklingGoblin.
Winnti is referenced as a real-world malware family that abuses in-memory patching techniques to intercept function calls and conceal activity.
A Linux ELF backdoor used for stealthy long-term access in cloud environments. It harvests cloud credentials from metadata services and local credential files across AWS, GCP, Azure, and Alibaba Cloud, encrypts the collected secrets, and exfiltrates them via an SMTP-based command-and-control channel. It also supports peer-to-peer coordination for lateral movement inside cloud networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.