Winnti 4.0 is a modular remote access Trojan used in long-running cyber espionage operations associated with multiple PRC-linked threat actors, including APT41. It represents a later evolution of the Winnti malware lineage and has been observed since at least 2016, with newer command-and-control protocol changes appearing by 2018. The malware is designed for flexible post-compromise control and supports multiple command-and-control transports, including TCP, TLS, HTTP, HTTPS, and UDP.
Winnti 4.0 uses custom encrypted packet formats and distinct protocol logic across its supported transports. Reported architectural characteristics include use of a loader-and-DAT-file initial component, AES-based initial encryption, and worker encryption that can rely on DPAPI or AES with a host-specific key. Its HTTP-based communications include an initial GET request followed by a POST request carrying the custom packet format, with additional metadata encoded in HTTP cookie values.
A notable feature of Winnti 4.0 is a server-mode capability that accepts inbound packets. This functionality has been assessed as useful for internal propagation or operator control on compromised hosts and may aid lateral movement after initial compromise. The malware’s modular RAT design and multi-protocol C2 support make it suitable for resilient long-term access and operational flexibility in targeted intrusions.
Winnti 4.0 has been tied to active and persistent command-and-control infrastructure over multiple years, with operators continuing to deploy new servers while retaining portions of older infrastructure. It is associated with espionage-focused activity rather than commodity crime and is relevant to defenders tracking PRC-linked intrusion sets and long-dwell enterprise compromises.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
I will explain how to emulate the protocols of two long-term pieces of malware used by PRC-linked cyber espionage threat actors: Winnti 4.0 and ShadowPad.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial encryption algorithm DES ... AES ... Worker encryption 1-byte XOR and nibble swap ... DPAPI or AES with host-specific key
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP. | As the configuration structure shows, the Worker component supports five C2 protocols: TCP, HTTP, HTTPS, TLS and UDP.
Supported protocols TCP/TLS/HTTP(S)/UDP ... Winnti 4.0 ... TCP/443 & 80 ... UDP 443 & 53
the Worker component looks to have few built-in remote access trojan (RAT) functionalities other than collecting the host information and executing a PE module plug-in downloaded from the C2.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modularized remote access trojan used for cyber espionage, supporting multiple command-and-control protocols. The article focuses on active Winnti 4.0 C2 servers that continued operating over the last two years.
Long-term APT malware variant with multiple C2 protocols (TCP, HTTP, HTTPS, TLS, UDP) and a server-mode function for lateral movement. The Worker component appears to have limited built-in RAT capability beyond collecting host information and executing PE plug-in modules downloaded from C2.
A Winnti malware variant whose long-term C2 infrastructure was analyzed via protocol emulation and internet-wide scanning. The content describes its custom encrypted C2 protocol over TCP, TLS, HTTP(S), and UDP, including server-mode behavior and handshake structure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.