WINERACK is a malware family associated with Linux environments that provides interactive remote access through a reverse shell implemented with statically linked Wine cmd.exe functionality to emulate Windows command prompt behavior. It has been documented performing host reconnaissance by enumerating running processes, active windows, and system services, and by collecting the current victim username. These behaviors indicate use as a post-compromise access tool for operator-driven command execution and environment discovery on infected systems. The use of Wine-based Windows command emulation on Linux distinguishes WINERACK from conventional native Linux backdoors and suggests an emphasis on familiar Windows-style shell interaction for operators. High-confidence reporting supports reconnaissance and post-exploitation functionality on Linux systems, but does not establish a specific initial infection vector or industry targeting from the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that can gather information on the victim username.
Gathers information on the victim username.
Backdoor malware capable of enumerating processes.
Backdoor/remote shell malware that creates a reverse shell and emulates Windows command prompt commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.