Winnti for Windows
MITRE ATT&CK: S0141 View on attack.mitre.org
Aliases: Winnti for Windows
- First seen
- 2010-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:56:47
Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:cn country_code:us country_code:de country_code:jp country_code:fr
Context
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.. The Linux variant is tracked separately under Winnti for Linux.
Detection coverage
- 419 Sigma rules
Malware & tools used
- Windows Service (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- File and Directory Discovery (attack-pattern)
- External Proxy (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Process Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Internal Proxy (attack-pattern)
- Rundll32 (attack-pattern)
- Bypass User Account Control (attack-pattern)
- System Information Discovery (attack-pattern)
- Compression (attack-pattern)
- Service Execution (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File Deletion (attack-pattern)
- Timestomp (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Web Protocols (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Environmental Keying (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- Winnti Group (threat-actor)
- Aquatic Panda (threat-actor)
Related threat objects
- Winnti (Windows) (malware)
Reports & references
- Kaspersky — 37029 (report)
- medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
- 401trg.github.io — Burning Umbrella (report)
- web.archive.org — Novetta Winntianalysis (report)
- MITRE ATT&CK — S0141 (report)
- Microsoft — Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp (report)