Winnti is a long-running malware family and backdoor platform associated with Chinese intrusion activity commonly referred to as the Winnti group, Winnti Umbrella, Blackfly, and overlapping clusters including APT41. First publicly documented in 2013 and active since at least 2009, it was initially prominent in intrusions against the video game industry, where operators stole source code, digital certificates, and other intellectual property and also pursued financially motivated objectives such as abuse of in-game economies. Over time, Winnti-linked operations expanded to pharmaceutical, telecommunications, semiconductor, energy, media, manufacturing, healthcare, education, government, and other sectors worldwide.
Winnti is best characterized as a modular backdoor with rootkit-assisted stealth. Early Windows variants used signed 64-bit kernel components to hide activity and network connections, and later variants included a driver known as NdisReroute that covertly redirected traffic from legitimate listening ports to the malware’s user-space component after receipt of a distinctive trigger packet. The malware has been observed using DLL side-loading and multi-component installation chains involving an installer, loader, and payload. It supports in-memory plugin loading and remote operator control, with capabilities including command execution, file transfer and file theft, process and service management, proxying, remote desktop enablement, and broader post-compromise operations. Some variants embedded victim or campaign identifiers directly in configuration data.
Winnti communications have evolved across generations. Documented variants used custom encrypted TCP protocols, covert port-reuse techniques, and in at least one case DNS tunneling implemented with iodine-derived code and long encoded subdomains. Public reporting also links the broader Winnti ecosystem to passive backdoors such as PortReuse and to supply-chain operations in which launchers decrypted and deployed Winnti-related payloads. The malware has also been associated with abuse of public web services and dead-drop style mechanisms for command-and-control support in related operations.
Delivery and installation methods vary by campaign. Historically observed vectors include spearphishing, compromise of software update mechanisms, malicious loaders and side-loading chains, and deployment after exploitation of public-facing applications or other footholds established by associated operators. Winnti has also appeared in Linux environments, including a Linux backdoor exposed in a pharmaceutical intrusion and later ELF samples classified as Winnti or closely related to PWNLNX. Reporting further ties Winnti-linked activity to PHP-based server-side malware frameworks that deploy ELF backdoors on Linux systems.
The malware family is most strongly associated with espionage and long-term persistence, but some operations linked to the same ecosystem also pursued cryptocurrency mining or financially motivated theft. Because the name Winnti is used both for the malware family and for a broader cluster of Chinese threat activity, reporting sometimes conflates the malware with the actor set; however, at high confidence, Winnti refers to a modular backdoor family used across multiple campaigns and sectors on both Windows and Linux.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
[16] The rush for CVE-2013-3906 - a hot commodity ... [17] Exploit Proliferation: Additional Threat Groups Acquire CVE-2013-3906
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Winnti. More than just a game,” ... “Recent Winnti Infrastructure and Samples,” ... “Winnti Abuses GitHub for C&C Communications” | “Winnti. More than just a game,” Securelist by Kaspersky, April 11, 2013
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
Sidewalk was recently documented by ESET, who attributed it to a new group it called SparklingGoblin, which it linked to the Winnti malware family.
The group intends to exfiltrate documents and email account credentials, as well as to further deploy advanced backdoors like ShadowPad and the Linux version of Winnti to conduct long-term espionage activities against its targets.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 exploits vulnerabilities in public-facing applications and deploys malware such as Winnti and ShadowPad to maintain persistence.
The group has since earned infamy for being involved in malicious activities associated with targeted attacks, such as deploying spear-phishing campaigns and building a backdoor.
The library used to hide Winnti’s system activity is a copy of the open-source userland rootkit Azazel, with minor changes. When executed, it will register symbols for multiple commonly used functions, including: open(), rmdir(), and unlink(), and modify their returns to hide the malware’s operations.
In some instances, Winnti operators wrote the names of their targets directly into the malware, obfuscated with a rolling XOR cipher.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
Kaspersky researchers uncovered that the digital signature used to sign the original Winnti malware was stolen from another video game vendor known as KOG... the Winnti group had used at least 18 stolen code-signing certificates in its campaigns
Inside the cloud network, the implant supports lateral movement by periodically sending UDP broadcast beacons to 255.255.255.255 on port 6006, allowing other compromised hosts to discover each other and share tasking without extra direct C2 traffic.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
a feature of recent versions of Winnti we came across in the Linux variant (as well as Windows) that allows the operators to initiate a connection directly to an infected host, without requiring a connection to a control server. This secondary communication channel may be used by operators when access to the hard-coded control servers is disrupted.
For years, TAU has reversed and emulated the network Command and Control (C2) protocols of high-profile malware families... Continuing its research, TAU has discovered additional Winnti 4.0 C2 servers actively used over the last two years.
According to the Breakglass Intelligence report, the backdoor uses an unusual but effective command-and-control strategy built around SMTP traffic over port 25, rather than more common HTTPS-based channels. This choice allows the implant to disguise its C2 as email traffic... All collected secrets are encrypted using a hardcoded AES-256 key and staged locally prior to exfiltration through the SMTP-based C2 channel.
prior reporting suggests that the operators commonly deploy plugins for remote command execution, file exfiltration, and socks5 proxying on the infected host.
The driver component of Winnti (aka "NdisReroute") is able to reroute network traffic from ports that are already occupied by legit applications to the malware's userspace component. The first packet of a TCP stream signals the driver that the stream shall be rerouted.
References include 'Attacks on East Asia using Google Code for Command and Control' and 'Winnti Abuses GitHub for C&C Communications.'
This component is primarily designed to handle communications and the deployment of modules directly from the command-and-control servers.
772 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family mentioned as part of ESET's attribution linkage for SparklingGoblin.
Winnti is referenced as a real-world malware family that abuses in-memory patching techniques to intercept function calls and conceal activity.
A Linux ELF backdoor used for stealthy long-term access in cloud environments. It harvests cloud credentials from metadata services and local credential files across AWS, GCP, Azure, and Alibaba Cloud, encrypts the collected secrets, and exfiltrates them via an SMTP-based command-and-control channel. It also supports peer-to-peer coordination for lateral movement inside cloud networks.
An ELF backdoor targeting Linux cloud workloads and harvesting cloud credentials across major cloud environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.