Winnti (ELF)

First seen
2009-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:56:49

Targeted industries: technology-and-telecommunications education-and-nonprofits energy-and-utilities government-and-public-sector

Targeted regions: country_code:cn country_code:us country_code:de country_code:jp

Context

Winnti (ELF) is a sophisticated malware family used by advanced threat actors for cyber espionage. It is commonly involved in attacks targeting technology and telecommunications sectors, and it often functions as a backdoor to facilitate further malicious activities.

Reports & references

  • medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
  • secureworks.com — Bronze Atlas (report)
  • MITRE ATT&CK — G0096 (report)
  • go.recordedfuture.com — Cta 2023 0808 (report)
  • intezer.com — Elf Malware Analysis 101 Linux Threats No Longer An Afterthought (report)
  • blog.exatrack.com — Melofee (report)
  • asec.ahnlab.com — 55785 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Winnti (report)
  • blog.xlab.qianxin.com — Glutton Stealthily Targets Mainstream Php Frameworks En (report)

External references