PWNLNX is a Linux malware family associated with the Winnti threat ecosystem and linked through code reuse and tradecraft similarities to other Linux implants in that lineage, including RedXOR. It is commonly described as a backdoor used in targeted intrusions against Linux systems. Public reporting places it within a broader cluster of Chinese state-linked or Winnti-umbrella activity focused on long-term access to enterprise and server environments.
The malware has been cited as sharing implementation details with other Winnti-associated Linux tools, including reused function names and overlapping development patterns. These similarities have made PWNLNX an important reference point in tracking the evolution of Linux malware within the Winnti lineage over multiple years. Reporting has also connected it to related Linux malware families and botnet tooling attributed to the same umbrella.
High-confidence public details in the supplied material support classifying PWNLNX as a Linux backdoor. It is associated with post-compromise operations rather than commodity mass infection, and its significance lies in its role as part of a mature Linux intrusion toolkit used by a long-running threat cluster. Specific initial infection vectors, persistence mechanisms, and victim sectors are not directly established here at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackTech with their new ELF_PLEAD malware and Winnti’s PWNLNX tool are recent examples.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
A 2.7 MB ELF binary with near-maximum entropy (7.997 bits per byte across ~832 KB of code). The obfuscation isn't packing -- it's a custom code virtualizer or instruction-level transformation that renders static analysis effectively impossible without dedicated devirtualization tooling.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
The most operationally significant capability is the backdoor's access to cloud instance metadata at 169.254.169.254 . This is the link-local address that every major cloud provider uses to serve instance credentials, API tokens, and configuration data to running workloads.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an earlier malware in the Winnti ELF lineage.
Linux backdoor associated in the content with the Winnti umbrella group and used as a comparison point for RedXOR due to similar code flow, pty shell capability, XML-based file listing, XOR-encoded network traffic, PortMap tunneling, and compiler artifacts.
Mentioned as another example of Linux malware/tooling evolution.
Linux backdoor associated with the Winnti group, used for persistent access and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.