Malware.View on attack.mitre.org
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.. The Linux variant is tracked separately under Winnti for Linux.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Winnti for Windows has the ability to encrypt and compress its payload. |
| T1027.015 Compression |
Winnti for Windows has the ability to encrypt and compress its payload. |
| T1036.005 Match Legitimate Resource Name or Location |
A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1057 Process Discovery |
Winnti for Windows can check if the explorer.exe process is responsible for calling its install function. |
| T1070.004 File Deletion |
Winnti for Windows can delete the DLLs for its various components from a compromised host. |
| T1070.006 Timestomp |
Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe. |
| T1071.001 Web Protocols |
Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications. |
| T1082 System Information Discovery |
Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP. |
| T1083 File and Directory Discovery |
Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution. |
| T1090.001 Internal Proxy |
The Winnti for Windows HTTP/S C2 mode can make use of a local proxy. |
| T1090.002 External Proxy |
The Winnti for Windows HTTP/S C2 mode can make use of an external proxy. |
| T1095 Non-Application Layer Protocol |
Winnti for Windows can communicate using custom TCP. |
| T1105 Ingress Tool Transfer |
The Winnti for Windows dropper can place malicious payloads on targeted systems. |
| T1106 Native API |
Winnti for Windows can use Native API to create a new process and to start services. |
| T1140 Deobfuscate/Decode Files or Information |
The Winnti for Windows dropper can decrypt and decompresses a data blob. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.