Winnti for Windows

MITRE ATT&CK: S0141 View on attack.mitre.org

Aliases: Winnti for Windows

First seen
2010-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:56:47

Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:cn country_code:us country_code:de country_code:jp country_code:fr

Context

Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.. The Linux variant is tracked separately under Winnti for Linux.

Detection coverage

  • 419 Sigma rules

Malware & tools used

  • Windows Service (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • External Proxy (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Process Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Internal Proxy (attack-pattern)
  • Rundll32 (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Compression (attack-pattern)
  • Service Execution (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File Deletion (attack-pattern)
  • Timestomp (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Web Protocols (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Environmental Keying (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • Kaspersky — 37029 (report)
  • medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
  • 401trg.github.io — Burning Umbrella (report)
  • web.archive.org — Novetta Winntianalysis (report)
  • MITRE ATT&CK — S0141 (report)
  • Microsoft — Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp (report)

External references