logo

APT41__2019__Winnti_Group_s_skip_2.0_A_Microsoft_SQL_Server_backdoor.pdf

ID: 7bbcd5fd-b9fb-47ce-98eb-83672e77b991

STIX ID: report--7bbcd5fd-b9fb-47ce-98eb-83672e77b991

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2019-10-21

Last Modified Date: 2019-10-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers describe 'skip-2.0', a sophisticated Winnti Group MSSQL backdoor that is delivered via a VMProtected launcher and a custom packer, injects into sqlserv.exe, hooks authentication and logging functions in sqllang.dll to allow access using a hardcoded 'magic' password while suppressing audit logs, and provides indicators of compromise and ATT&CK technique mappings.