ESET reported that the Winnti Group used a previously unanalyzed passive backdoor called PortReuse and tied it to a broader malware arsenal that also includes updated ShadowPad variants and a VMProtect-based launcher. PortReuse injects into processes already listening on common ports, waits for a magic packet, and covertly enables attacker control while forwarding legitimate traffic, helping it blend into normal network activity. The launcher decrypts either PortReuse or ShadowPad payloads with RC5 keys derived from the victim machine’s volume serial number, a technique ESET said reinforced the technical links across the toolset.
The research connected multiple high-profile software supply-chain compromises—including CCleaner, NetSarang, Asus ShadowHammer, and several 2018 compromised games and software incidents—to the same broader Winnti ecosystem through shared tooling, cryptography, and tradecraft. ESET also said some of the 2018 third-stage payloads were XMRig Monero miners, indicating cryptocurrency mining as one operational objective. With assistance from Censys, the company identified eight Internet-facing systems matching PortReuse’s HTTP signature at a major Asian mobile hardware and software manufacturer and said it notified the victim.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
In its October 2019 white paper, ESET analyzed the Winnti Group's malware arsenal, documented the PortReuse backdoor, and assessed that strong technical links connected the CCleaner, NetSarang, Asus ShadowHammer, and 2018 compromised games/software incidents to the same broader Winnti ecosystem.
ESET observed that ShadowPad was still being updated and used multiple times in 2019, including variants with random module IDs and additional obfuscation. The report also noted ShadowPad samples retrieving encrypted C2 information from public services such as Google Docs, Steam Community, GitHub, Pastebin, and MSDN profiles.
ESET reported that decrypted third-stage payloads from 2018 compromised games and software supply-chain attacks were XMRig Monero miners, indicating cryptocurrency mining as one objective of the operators.
After identifying the exposed systems, ESET notified the affected Asian mobile hardware and software manufacturer and worked with it on remediation.
With help from Censys, ESET identified eight Internet-facing systems matching PortReuse's HTTP signature and determined they all belonged to a major Asian mobile hardware and software manufacturer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceattack.mitre.org
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.