WingBird is a Windows malware family associated with exploitation of Microsoft Office and .NET-related vulnerabilities, including observed delivery through malicious Office documents exploiting CVE-2017-0199 and association with CVE-2017-8759. It has been described as sharing characteristics with FinFisher/FinSpy and has been observed as a heavily obfuscated dropper with anti-analysis features.
WingBird uses DLL side-loading to execute malicious code, including use of a spoofed service built from a copied system binary to load a malicious DLL. It establishes persistence by registering an autostart Windows service masquerading as a legitimate component. The malware also performs multiple process injections to hijack legitimate system processes for execution and evasion.
Post-compromise behavior includes checking for the presence of security software, specifically antivirus products, indicating security-software discovery for defense evasion and execution gating. WingBird has also been reported exploiting CVE-2016-4117 to obtain elevated privileges. Cleanup behavior includes deleting its payload and the parent process after file-copy operations, reducing forensic visibility.
The family is primarily a Windows threat and is best characterized as a loader or dropper used to install or launch additional malicious components while employing persistence, privilege escalation, process injection, DLL side-loading, and anti-analysis techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-8759 Vulnerable Products: Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 Associated Malware: FINSPY, FinFisher, WingBird Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-8759 ... Associated Malware: FINSPY, FinFisher, WingBird
Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
"we began detecting some suspicious installers of legitimate applications, backdoored with a relatively small obfuscated downloader... the backdoored installers are nothing more than first stage implants"; "legitimate applications backdoored with FinSpy... TeamViewer, VLC Media Player, WinRAR"
Malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets. | According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
"Anchor can create and execute services to load its payload"; "APT32's backdoor has used Windows services as a way to execute its malicious payload"; "Ragnar Locker has used sc.exe to execute a service that it creates"; "Shamoon creates a new service named 'ntssrv' to execute the payload"
The content repeatedly describes malware and threat actors injecting shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, cmd.exe, lsass.exe, and browser processes.
APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.
The content repeatedly describes malware and threat actors injecting shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, cmd.exe, lsass.exe, and browser processes.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware that hijacks system processes through repeated process injection.
Backdoor malware that deletes its payload and parent process after file-copy operations.
Malware that side-loads a malicious DLL as part of a spoofed service.
Backdoor that registers an autostart service named Audit Service using a copied lsass.exe file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.