Winnti (ELF)
- First seen
- 2009-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:56:49
Targeted industries: technology-and-telecommunications education-and-nonprofits energy-and-utilities government-and-public-sector
Targeted regions: country_code:cn country_code:us country_code:de country_code:jp
Context
Winnti (ELF) is a sophisticated malware family used by advanced threat actors for cyber espionage. It is commonly involved in attacks targeting technology and telecommunications sectors, and it often functions as a backdoor to facilitate further malicious activities.
Reports & references
- medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
- secureworks.com — Bronze Atlas (report)
- MITRE ATT&CK — G0096 (report)
- go.recordedfuture.com — Cta 2023 0808 (report)
- intezer.com — Elf Malware Analysis 101 Linux Threats No Longer An Afterthought (report)
- blog.exatrack.com — Melofee (report)
- asec.ahnlab.com — 55785 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Winnti (report)
- blog.xlab.qianxin.com — Glutton Stealthily Targets Mainstream Php Frameworks En (report)