APT41__2019__Winnti_Group_s_skip_2.0_A_Microsoft_SQL_Server_backdoor.pdf
ID: 7bbcd5fd-b9fb-47ce-98eb-83672e77b991
STIX ID: report--7bbcd5fd-b9fb-47ce-98eb-83672e77b991
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2019-10-21
Last Modified Date: 2019-10-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers describe 'skip-2.0', a sophisticated Winnti Group MSSQL backdoor that is delivered via a VMProtected launcher and a custom packer, injects into sqlserv.exe, hooks authentication and logging functions in sqllang.dll to allow access using a hardcoded 'magic' password while suppressing audit logs, and provides indicators of compromise and ATT&CK technique mappings.
