ATT&CKSoftwareWinnti for Windows

Winnti for Windows

S0141

Malware.View on attack.mitre.org

About this malware

Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.. The Linux variant is tracked separately under Winnti for Linux.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Winnti for Windows has the ability to encrypt and compress its payload.

T1027.015
Compression

Winnti for Windows has the ability to encrypt and compress its payload.

T1036.005
Match Legitimate Resource Name or Location

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1057
Process Discovery

Winnti for Windows can check if the explorer.exe process is responsible for calling its install function.

T1070.004
File Deletion

Winnti for Windows can delete the DLLs for its various components from a compromised host.

T1070.006
Timestomp

Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.

T1071.001
Web Protocols

Winnti for Windows has the ability to use encapsulated HTTP/S in C2 communications.

T1082
System Information Discovery

Winnti for Windows can determine if the OS on a compromised host is newer than Windows XP.

T1083
File and Directory Discovery

Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution.

T1090.001
Internal Proxy

The Winnti for Windows HTTP/S C2 mode can make use of a local proxy.

T1090.002
External Proxy

The Winnti for Windows HTTP/S C2 mode can make use of an external proxy.

T1095
Non-Application Layer Protocol

Winnti for Windows can communicate using custom TCP.

T1105
Ingress Tool Transfer

The Winnti for Windows dropper can place malicious payloads on targeted systems.

T1106
Native API

Winnti for Windows can use Native API to create a new process and to start services.

T1140
Deobfuscate/Decode Files or Information

The Winnti for Windows dropper can decrypt and decompresses a data blob.

View all 22 procedure examples

Groups that use it2

Campaigns0

None recorded.

References5

  1. 401 TRG Winnti Umbrella May 2018 Open source
    Hegel, T. (2018, May 3). Burning Umbrella: An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers. Retrieved July 8, 2018.
  2. Chronicle Winnti for Linux May 2019 Open source
    Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020.
  3. Kaspersky Winnti April 2013 Open source
    Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.
  4. Microsoft Winnti Jan 2017 Open source
    Cap, P., et al. (2017, January 25). Detecting threat actors in recent German industrial attacks with Windows Defender ATP. Retrieved February 8, 2017.
  5. Novetta Winnti April 2015 Open source
    Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.