GinWui is a Windows malware family historically described as a rootkit and remote-access backdoor associated with the Chinese hacking group Network Crack Program Hacker (NCPH), founded by Tan Dailin (Wicked Rose). It has been linked in reporting to early Chinese state-aligned intrusion activity and was cited in connection with operations targeting U.S. government and private-sector entities in 2006. GinWui is notable as one of the early homegrown Chinese remote-access malware tools and is frequently discussed in the context of the evolution of China’s offensive cyber ecosystem.
On infected Windows systems, GinWui has been observed using registry-based DLL injection for both stealth and persistence, specifically by modifying AppInit_DLLs so that its code is loaded into processes that load User32.dll. This behavior supports persistent execution and process injection into legitimate processes, aligning with its characterization as a rootkit-style backdoor designed to evade detection and maintain access. The malware is therefore associated with defense evasion, persistence, and post-compromise access on Windows hosts.
GinWui is tied through multiple accounts to developers and operators connected to NCPH, including Tan Dailin and Zhao Jibin/WHG, and has been referenced in analyses of overlap between Chinese intrusion clusters later tracked under labels such as APT17 and APT41. High-confidence reporting supports its role as a Chinese-developed backdoor/rootkit used in espionage-oriented operations rather than commodity cybercrime. Publicly available information in this context does not establish a specific initial infection vector with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They created the GinWui rootkit, one of China’s first homegrown remote-access backdoors and then, experts believe, used it and dozens of zero-day exploits they wrote in a series of “unprecedented” hacks against US companies and government entities over the spring and summer of 2006.
…operations involving the GinWui rootkit, which was developed by NCHP members…
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-developed rootkit and remote-access backdoor used by Tan Dailin’s NCPH group in intrusions against US companies and government entities.
A rootkit linked in the content to WHG and the Network Crack Program Hacker group.
A trojan shown modifying the AppInit_DLLs registry key for both injection and persistence.
Trojan shown modifying the AppInit_DLLs registry key for both injection and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.