Winnti is a long-running malware family and broader malware lineage associated in the provided content with Chinese state-sponsored activity, especially clusters tracked as Winnti Group and APT41. The content describes both Windows and Linux variants. The Linux variant consists of a main backdoor, libxselinux, and a companion library, libxselinux.so, used to hide activity on infected systems; libxselinux.so is described as a modified Azazel-derived userland rootkit. Linux Winnti samples decode XOR-obfuscated embedded configuration data containing command-and-control infrastructure and campaign designators, and support outbound communications over ICMP, HTTP, and custom TCP/UDP protocols. Chronicle also observed a passive inbound communication feature in Linux and Windows Winnti variants that allows operators to directly initiate connections to infected hosts, including validation using magic value 0xABC18CBA. Detection content references YARA rules for the Linux main backdoor and an azazel_fork variant, with sample SHA-256 values ae9d6848f33644795a0cc3928a76ea194b99da3c10f802db22034d9f695a0c23 and 4741c2884d1ca3a40dadd3f3f61cb95a59b11f99a0f980dbadc663b85eb77a2a.
The content also describes newer Linux Winnti-family ELF backdoors attributed with high confidence to APT41/Winnti. These implants target Linux workloads in AWS, GCP, Azure, and Alibaba Cloud, harvest cloud instance metadata and credentials from 169.254.169.254 and local credential/configuration files, and use typosquatted infrastructure including ai.qianxing.co, ns1.a1iyun.top, and ai.aliyuncs.help resolving to 43.99.48.196. Reported behaviors include SMTP-based command and control over port 25, selective EHLO-token-based server responses, and UDP broadcast beacons to 255.255.255.255:6006 for host discovery or lateral movement. One cited sample had MD5 f1403192ad7a762c235d670e13b703c3 and was classified by MalwareBazaar and ReversingLabs as Winnti/Linux.Backdoor.Winnti, with Intezer reporting code reuse linking it to the Winnti lineage.
Across the content, Winnti is repeatedly associated with long-term espionage, persistence, credential theft, file operations, shell execution, proxying, and deployment alongside other tooling such as ShadowPad, PlugX, China Chopper, Cobalt Strike, and related Linux implants. Reported infection and deployment vectors include exploitation of public-facing applications, DLL search-order hijacking on Windows, malicious shell scripts and preload-based persistence on Linux, and use in targeted campaigns against gaming companies, pharmaceutical organizations, media, government entities, universities, and cloud-hosted workloads. Additional indicators mentioned include Windows path C:\Windows\System32\oci.dll in one Hong Kong university intrusion, Linux component names libxselinux and libxselinux.so, and campaign-linked C2 naming patterns such as w[target].livehost.live:443 and w[target].dnslookup.services:443.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This server was known to be used to stage archives containing an installer for the Linux version of the Winnti rootkit.
"China-Linked Group TAG-28 Targets India’s “The Times Group” and UIDAI (Aadhaar) Government Agency With Winnti Malware"
"...attempting to install a variant of the Winnti malware family..."
"This attack is thought to be of Chinese origins and utilized the Winnti backdoor."
"This attack is thought to be of Chinese origins and utilized the Winnti backdoor."
"This attack is thought to be of Chinese origins and utilized the Winnti backdoor."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 exploits vulnerabilities in public-facing applications and deploys malware such as Winnti and ShadowPad to maintain persistence.
It has been linked to supply chain compromises and for hacking into popular software vendors. Well known software titles with significant installation bases were compromised with malware.
prior reporting suggests that the operators commonly deploy plugins for remote command execution, file exfiltration, and socks5 proxying on the infected host.
The library used to hide Winnti’s system activity is a copy of the open-source userland rootkit Azazel, with minor changes. When executed, it will register symbols for multiple commonly used functions, including: open(), rmdir(), and unlink(), and modify their returns to hide the malware’s operations.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
Inside the cloud network, the implant supports lateral movement by periodically sending UDP broadcast beacons to 255.255.255.255 on port 6006, allowing other compromised hosts to discover each other and share tasking without extra direct C2 traffic.
a feature of recent versions of Winnti we came across in the Linux variant (as well as Windows) that allows the operators to initiate a connection directly to an infected host, without requiring a connection to a control server. This secondary communication channel may be used by operators when access to the hard-coded control servers is disrupted.
Winnti malware handles outbound communications using multiple protocols including: ICMP, HTTP, as well as custom TCP and UDP protocols.
According to the Breakglass Intelligence report, the backdoor uses an unusual but effective command-and-control strategy built around SMTP traffic over port 25, rather than more common HTTPS-based channels. This choice allows the implant to disguise its C2 as email traffic... All collected secrets are encrypted using a hardcoded AES-256 key and staged locally prior to exfiltration through the SMTP-based C2 channel.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Winnti is referenced as a real-world malware family that abuses in-memory patching techniques to intercept function calls and conceal activity.
A Linux ELF backdoor used for stealthy long-term access in cloud environments. It harvests cloud credentials from metadata services and local credential files across AWS, GCP, Azure, and Alibaba Cloud, encrypts the collected secrets, and exfiltrates them via an SMTP-based command-and-control channel. It also supports peer-to-peer coordination for lateral movement inside cloud networks.
An ELF backdoor targeting Linux cloud workloads and harvesting cloud credentials across major cloud environments.
An obfuscated x86_64 ELF backdoor attributed in the content to the Winnti lineage. It communicates with typosquatted C2 domains hosted on Alibaba Cloud, uses SMTP port 25 as a covert command channel, harvests cloud instance metadata and credentials from AWS, GCP, Azure, and Alibaba Cloud, and performs UDP broadcast-based network discovery for lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.