WinMM is a Windows malware family that functions as a backdoor or remote access implant. It has been observed using HTTP for command-and-control communications and is typically configured with both primary and backup command-and-control domains, indicating built-in communication resiliency and failover capability. On infected systems, WinMM performs host reconnaissance by collecting information about process creation through a WH_CBT Windows hook and by querying local account context with NetUserGetInfo to determine whether it is running under an administrative account. These behaviors support operator awareness of execution context and may inform subsequent post-compromise actions. The malware targets Windows systems and exhibits characteristics consistent with a persistent interactive implant designed for continued remote control and situational awareness on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that uses NetUser-GetInfo to determine whether it is running under an admin account.
Malware typically configured with primary and backup C2 domains.
Uses NetUser-GetInfo to determine whether it is running under an Admin account.
Backdoor malware that uses a Windows hook to collect process creation information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.