WINTAPIX is a Windows kernel-mode passive backdoor associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with Iran’s Ministry of Intelligence and Security. It has been used in long-term, stealth-focused intrusions targeting high-priority networks in the Middle East, particularly government and telecommunications organizations.
WINTAPIX is notable for kernel-driver tradecraft designed to reduce visibility to endpoint and network defenses. It communicates through undocumented IOCTL mechanisms rather than conventional outbound command-and-control traffic, aligning with UNC1860’s broader use of passive implants that wait for inbound tasking and thereby complicate detection by EDR and network-monitoring systems. Reporting also notes code similarities between WINTAPIX and another UNC1860-associated malicious driver tracked as TOFUDRV, indicating a shared development lineage or closely related functionality.
Within UNC1860 operations, WINTAPIX forms part of a broader ecosystem that includes web shells, droppers, loaders, passive backdoors, and operator controllers used to establish access, maintain persistence, and support follow-on operations. UNC1860 commonly gains entry by exploiting vulnerable internet-facing servers and then deploys stealthier implants for durable access. The actor has demonstrated strong Windows internals expertise, including kernel and file-system manipulation, and has used passive malware families such as WINTAPIX to evade standard detection mechanisms while sustaining covert access in victim environments.
WINTAPIX is best characterized as a stealth-oriented kernel backdoor used for post-compromise persistence and defense evasion in espionage-focused campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Both passive implants TOFUDRV and TOFULOAD leverage undocumented Input/Output Control commands for communication... using them promises lower detection rates and possibilities akin to filtering drivers, which act as middlemen allowing for the inspection, modification, or blocking of network traffic before it reaches the device or application, as well as assets like file system objects and registry entries.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems. These implants operate without initiating outbound traffic, making them difficult to detect through traditional network monitoring tools.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.