Winnti is a modular backdoor family associated with the China-linked Winnti umbrella and APT41/Blackfly activity. First publicly described in 2013, it has been used in long-running espionage and financially motivated intrusions affecting gaming, pharmaceutical, telecommunications, semiconductor, technology, and other organizations. Windows variants have used a kernel driver/rootkit component, also known as NdisReroute, to conceal activity and redirect selected traffic from legitimate listening ports to a user-mode backdoor after receipt of a specially formed network trigger. Some variants use DNS tunneling, including an implementation incorporating iodine-derived code, for command-and-control communication. Winnti has been installed through DLL search-order hijacking and side-loading of malicious DLLs by legitimate executables, and Windows installers have used Rundll32 to load DLL components. Linux Winnti backdoor variants have also been identified, including an intrusion affecting a German pharmaceutical organization. The family has historically supported theft of data and files and has been deployed alongside other Winnti ecosystem tooling, including ShadowPad and PlugX.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
[16] The rush for CVE-2013-3906 - a hot commodity ... [17] Exploit Proliferation: Additional Threat Groups Acquire CVE-2013-3906
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Lusca [is] known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families.
“Winnti. More than just a game,” ... “Recent Winnti Infrastructure and Samples,” ... “Winnti Abuses GitHub for C&C Communications” | “Winnti. More than just a game,” Securelist by Kaspersky, April 11, 2013
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
In April 2013, Kaspersky disclosed a report called “Winnti - More than just a game". The researchers reported that in Q3 2011, the Winnti group's malware was detected on a large number of computers...
Sidewalk was recently documented by ESET, who attributed it to a new group it called SparklingGoblin, which it linked to the Winnti malware family.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 exploits vulnerabilities in public-facing applications and deploys malware such as Winnti and ShadowPad to maintain persistence.
The group has since earned infamy for being involved in malicious activities associated with targeted attacks, such as deploying spear-phishing campaigns and building a backdoor.
The library used to hide Winnti’s system activity is a copy of the open-source userland rootkit Azazel, with minor changes. When executed, it will register symbols for multiple commonly used functions, including: open(), rmdir(), and unlink(), and modify their returns to hide the malware’s operations.
In some instances, Winnti operators wrote the names of their targets directly into the malware, obfuscated with a rolling XOR cipher.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
Kaspersky researchers uncovered that the digital signature used to sign the original Winnti malware was stolen from another video game vendor known as KOG... the Winnti group had used at least 18 stolen code-signing certificates in its campaigns
Inside the cloud network, the implant supports lateral movement by periodically sending UDP broadcast beacons to 255.255.255.255 on port 6006, allowing other compromised hosts to discover each other and share tasking without extra direct C2 traffic.
Old tool we created and used to sniff and decrypt Winnti's traffic within networks after nearly a year to reverse this shit.
a feature of recent versions of Winnti we came across in the Linux variant (as well as Windows) that allows the operators to initiate a connection directly to an infected host, without requiring a connection to a control server. This secondary communication channel may be used by operators when access to the hard-coded control servers is disrupted.
For years, TAU has reversed and emulated the network Command and Control (C2) protocols of high-profile malware families... Continuing its research, TAU has discovered additional Winnti 4.0 C2 servers actively used over the last two years.
According to the Breakglass Intelligence report, the backdoor uses an unusual but effective command-and-control strategy built around SMTP traffic over port 25, rather than more common HTTPS-based channels. This choice allows the implant to disguise its C2 as email traffic... All collected secrets are encrypted using a hardcoded AES-256 key and staged locally prior to exfiltration through the SMTP-based C2 channel.
prior reporting suggests that the operators commonly deploy plugins for remote command execution, file exfiltration, and socks5 proxying on the infected host.
The driver component of Winnti (aka "NdisReroute") is able to reroute network traffic from ports that are already occupied by legit applications to the malware's userspace component. The first packet of a TCP stream signals the driver that the stream shall be rerouted.
References include 'Attacks on East Asia using Google Code for Command and Control' and 'Winnti Abuses GitHub for C&C Communications.'
This component is primarily designed to handle communications and the deployment of modules directly from the command-and-control servers.
772 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family mentioned as part of ESET's attribution linkage for SparklingGoblin.
Winnti is referenced as a real-world malware family that abuses in-memory patching techniques to intercept function calls and conceal activity.
A Linux ELF backdoor used for stealthy long-term access in cloud environments. It harvests cloud credentials from metadata services and local credential files across AWS, GCP, Azure, and Alibaba Cloud, encrypts the collected secrets, and exfiltrates them via an SMTP-based command-and-control channel. It also supports peer-to-peer coordination for lateral movement inside cloud networks.
An ELF backdoor targeting Linux cloud workloads and harvesting cloud credentials across major cloud environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.