logo

APT41__2019__Winnti_More_than_just_Windows_and_Gates.pdf

ID: 2f9df88c-f8d4-4d0f-bb51-aaf20f70261a

STIX ID: report--2f9df88c-f8d4-4d0f-bb51-aaf20f70261a

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2019-05-16

Last Modified Date: 2019-05-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Chronicle provides a technical analysis of a Linux variant of the Winnti malware family, documenting two components (a backdoor and an Azazel-derived userland rootkit), embedded configuration decoding, multiple hardcoded C2 addresses, and a passive inbound listener feature that allows operators to initiate connections to infected hosts; the report includes file hashes, decoded config examples, YARA rules, and numerous IoCs tied to distinct campaign designators.