Security researchers and incident responders have tied a broad set of espionage and intrusion activity to the Winnti ecosystem, a China-linked threat cluster active for years against gaming companies, software vendors, and enterprise networks worldwide. Early reporting described intrusions used to steal source code, digital certificates, and other intellectual property, while later investigations connected the same ecosystem to major supply-chain compromises including CCleaner, NetSarang, ShadowHammer, and other software incidents. Researchers also found evidence that some operations monetized access through cryptocurrency mining and in-game fraud, and that operators tailored malware configurations to specific victims and campaigns.
Technical analysis shows Winnti operators evolving their tooling and infrastructure with modular backdoors such as PortReuse, ShadowPad, and newer malware linked with moderate confidence such as Glutton, while continuing to hide command-and-control through methods including GitHub-hosted encrypted C2 data, passive backdoors on common service ports, and rootkit-assisted traffic rerouting via NdisReroute. Defenders published multiple ways to detect the threat, including YARA rules, configuration parsers, PCAP and live-network detectors for the distinctive Winnti HELO handshake, Nmap scripts that can identify infected hosts and extract host metadata, and internet-scale tracking of Winnti 4.0 and ShadowPad servers. VMware reported dozens of active Winnti 4.0 servers still online, underscoring that the malware family’s infrastructure remains persistent and operational.

TTPs, infrastructure, and targeting history in one profile.
30 events from the most recent confirmed update back to the earliest known activity.
XLab documented the previously unreported Glutton PHP malware framework and attributed it with moderate confidence to Winnti based on the delivered ELF backdoor and supporting C2 behavior.
XLab detected anomalous activity on April 29, 2024, involving 172.247.127.210 distributing an ELF-based Winnti backdoor tied to the Glutton framework.
XLab found that IP address 172.247.127.210 had distributed a malicious PHP file named init_task.txt on December 20, 2023, predating later Glutton activity.
The VB 2022 presentation says the ShadowPad scanning program added UDP/443 for Variant1 and HTTP/80 for Variant3 in June 2022.
VMware TAU said it identified more active Winnti 4.0 command-and-control servers over the prior two years and released updated indicators covering 43 servers across 34 unique IP addresses.
According to the VB 2022 presentation, ShadowPad scanning expanded in October 2021 to include TCP/443 and UDP/53 for Variant1.
The VB 2022 presentation says the ShadowPad scanning timeline began in September 2021 with HTTP/443 coverage for Variants 2 and 3.
The VB 2022 presentation states that scanning for ShadowPad command-and-control infrastructure began in 2021.
With help from Censys, ESET found eight Internet-facing systems matching PortReuse's HTTP signature, all belonging to a major Asian mobile hardware and software manufacturer, and notified the victim.
ESET's October 2019 white paper analyzed the Winnti Group's malware arsenal, documented the PortReuse backdoor, and argued that CCleaner, NetSarang, Asus ShadowHammer, and 2018 software compromises were strongly linked to the same ecosystem.
A joint investigation by BR and NDR published scripts and rulesets for analyzing Winnti, including YARA hunting content and methods for identifying affected networks through campaign identifiers.
A later VB 2022 presentation states that internet-wide scanning for Winnti 4.0 command-and-control infrastructure began in 2019.
TKCERT published an Nmap NSE script that probes hosts for Winnti backdoor or rootkit infections and can retrieve basic host information from infected systems.
Sample output in the winnti-detector project shows a suspected Winnti session setup over UDP on 2018-03-06.
TKCERT published a network-based detector for Winnti malware communications that identifies the distinctive 16-byte initial packet used to reroute traffic.
TKCERT published a Suricata Lua-based ruleset to detect the 16-byte 'Winnti HELO' handshake used by certain Winnti malware variants. The release documented byte-level details of the initial TCP packet and provided deployment instructions for Suricata.
Sample output in the winnti-detector project shows a suspected Winnti TCP session setup detected in a PCAP file on 2018-01-23.
Trend Micro analyzed 2014-2015 domain registrations and malware-linked infrastructure, identifying a suspected Winnti-associated operator using the handle Hack520 and tying related domains and a Hong Kong-hosted /22 'Pig network' to Winnti command-and-control activity. The report also said previously unreported malware samples and linked domains led researchers to additional C2 servers.
Trend Micro said the most recent activity it tracked on the GitHub account used in the Winnti campaign was on March 12, 2017.
Trend Micro described a Winnti campaign that used GitHub-hosted HTML pages to store encrypted references to real C2 servers for BKDR64_WINNTI.ONM.
The winnti-detect Nmap script documentation identifies Version 1.0 with a date of 2016-09-26.
Trend Micro tracked the earliest activity on the GitHub account used for Winnti C2 communications to August 17, 2016.
Trend Micro said the same GitHub account created a benign-looking repository named mobile-phone-project in June 2016.
Trend Micro reported that the GitHub account later used in a Winnti command-and-control scheme was created in May 2016.
Kaspersky reported that a stolen MGAME Corp certificate was used in malware targeting Uyghur activists in March 2013.
Kaspersky documented Winnti as a Chinese-origin threat actor targeting the gaming industry, estimating at least 35 infected companies and detailing its malware, infrastructure, and certificate theft practices.
In September 2012, an anonymous gaming company identified as CompanyXYZ reported suspicious directories, archived intellectual property, and outbound connections from servers and domain controllers.
Kaspersky said a stolen YNK Japan certificate was used in the 2011 attacks against Cyworld and Nate and was later seen in malware targeting Tibetan and Uyghur activists.
Kaspersky reported that the Winnti group had been active against online gaming companies since at least 2009, marking the earliest stated start of the campaign.
Kaspersky concluded that infrastructure later associated with Winnti dated back to 2007, before shifting from FakeAV-related activity to gaming-company intrusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
blog.xlab.qianxin.com
Open sourceblogs.vmware.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceblog.trendmicro.com
Open sourcewelivesecurity.com
Open sourcevirusbulletin.com
Open sourcemedia.kasperskycontenthub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.