PortReuse is a Windows backdoor associated with the Winnti Group. It is designed as a passive network implant that covertly hijacks an existing network-facing service by injecting into a process already listening on a TCP port, allowing the compromised host to continue serving legitimate traffic while also accepting attacker-controlled sessions triggered by specially crafted packets. This design reduces exposure compared with malware that opens a new listening socket and helps the implant blend into normal server activity.
The malware has a modular architecture that includes loader, network interception, command handling, and process-transfer components communicating through named pipes. Its loader decrypts and launches additional packed modules and injects payloads into target processes. The network component hooks Windows networking-related APIs to inspect inbound traffic for trigger packets, including variants that blend activation traffic into protocols such as DNS. Some variants also use Windows URL prefix registration to intercept HTTP requests on commonly used service ports. Observed targets include ports commonly associated with DNS, web services, remote desktop, and remote management.
Once activated, PortReuse decrypts attacker traffic and provides a broad remote administration feature set. Documented capabilities include directory listing, file copy, move, deletion, file read and write, process enumeration and termination, timestamp modification, command execution, and network proxying. These functions make it suitable for stealthy long-term access and post-compromise operations on server systems.
PortReuse also incorporates defense-evasion measures. Legitimate traffic is forwarded to the real application so the original service continues to function, masking the compromise. At least one variant disables Event Tracing for Windows by patching telemetry-related functionality. The malware shares code, packing, and cryptographic traits with other Winnti tooling, including ShadowPad, Inner-Loader, and skip-2.0, and has been linked to broader Winnti intrusion activity including supply-chain compromises and long-term intrusions into enterprise environments. Public reporting has tied PortReuse deployments to compromises affecting a major Asian mobile hardware and software manufacturer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This report documents a previously unanalyzed backdoor used by the Winnti Group. Called PortReuse by its authors, this Windows backdoor is a passive network implant that injects itself into a process that is already listening on a network port and waits for an incoming magic packet to trigger the malicious code.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor referenced for architectural similarity (notably communications handling) to PipeMon; no additional technical details provided here.
A Winnti Group backdoor referenced as a closely related tool sharing the same custom packer, VMProtected launcher, Inner-Loader injector lineage, and similar hooking techniques with skip-2.0.
A backdoor referenced for its shared tradecraft with other Winnti Group tooling (notably RC5 encryption keyed from the victim system drive volume ID and use of a VMProtected launcher in prior campaigns).
A modular passive network implant/backdoor that injects into processes already listening on common TCP ports, hooks network receive functions, waits for magic packets, forwards legitimate traffic, and supports command execution, file operations, process injection, and proxying via named pipes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.