Winnti for Windows — Malware Profile
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.. The Linux variant is tracked separately under Winnti for Linux.
MITRE ATT&CK techniques (22)
- T1027.013 Encrypted/Encoded File
- T1027.015 Compression
- T1036.005 Match Legitimate Resource Name or Location
- T1057 Process Discovery
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1090.001 Internal Proxy
- T1090.002 External Proxy
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1140 Deobfuscate/Decode Files or Information
- T1218.011 Rundll32
- T1480.001 Environmental Keying
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1569.002 Service Execution
- T1573.001 Symmetric Cryptography