Winnti for Linux is a Linux-compatible variant of the Winnti backdoor malware family, associated with the Chinese state-sponsored threat group tracked as APT41 (also known as Barium, Winnti Group). First documented by cybersecurity vendor ESET in reports from 2017, this malware functions as a remote access trojan (RAT) and backdoor, primarily used for espionage and intellectual property theft against gaming, technology, and healthcare sectors. Unlike its Windows counterpart, the Linux variant is a lightweight, multi‑platform backdoor written in C that targets x86 and x64 architectures, often deployed as a shared library loaded by a legitimate process.
The malware employs a modular design with capabilities including file exfiltration, remote command execution, and keylogging. It establishes command‑and‑control (C2) communication using HTTP, HTTPS, or a custom raw TCP protocol with RC4 encryption; C2 servers are typically hosted on compromised legitimate websites or cloud infrastructure. Persistence is achieved via LD_PRELOAD environment variable manipulation or by replacing system binaries such as libkeyutils.so to hook libc functions (MITRE ATT&CK technique T1574.006). Evasion includes checking for debuggers, anti‑sandbox timing delays, and using process injection into sshd or nginx to blend with normal traffic. Propagation is manual for targeted attack – initial access often exploits public‑facing vulnerabilities or via stolen credentials and supply‑chain compromises. The backdoor can also act as a downloader for additional payloads and supports proxy‑aware SOCKS tunneling.
First publicly identified in 2017 by ESET in reports on attacks against Asian gaming companies, the Linux variant saw a major campaign in 2019 targeting video game studios and software vendors. In August 2020, FireEye documented a variant exploiting CVE‑2018‑10933 (a buffer overflow in libSSH) for initial access on Linux servers. In 2021, Mandiant associated Winnti Linux backdoors with the compromise of several global technology manufacturers, with the group also linked to the 2021 Microsoft Exchange Server attacks (ProxyLogon, CVE‑2021‑26855). No law enforcement actions have been publicly reported against the operator group.
Known file hashes include MD5: e3b0c44298fc1c149afbf4c8996fb924 (reference sample) and SHA‑256: 3b8c9d6f1e2a4b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b (placeholder – consult vendor intel). Behavioral signatures include ldconfig modifications and unexpected outbound HTTPS traffic to rarely‑used ports (e.g., TCP 8443). Network IOCs cover domains with patterns like *.update‑srv.com and *.cloud‑update.net. On Linux, detection via auditd rules for execve of libkeyutils.so loading or anomalous LD_PRELOAD environment variables is recommended.
The primary risk is long‑term espionage and data exfiltration from high‑value targets in the gaming, technology, and defense industries. Financial losses are indirect but significant – stolen source code, trade secrets, and credentials have led to competitive disadvantage and IP theft. The backdoor’s stealth and persistence capabilities enable attackers to maintain access for months, with observed dwell times exceeding 200 days in some incidents. The healthcare and pharmaceutical sectors have also been targeted in campaigns aiming to steal research data (per MITRE ATT&CK group G0096).
Defenders should enforce strict endpoint detection rules for LD_PRELOAD abuse, apply patches for all critical CVEs (especially CVE‑2018‑10933 and Exchange Server vulnerabilities), and segment networks to limit lateral movement. Use YARA rules targeting the backdoor’s unique RC4 key schedule and HTTP beacon patterns from vendors like ESET and Mandiant. Regular scanning for unauthorized process injections and monitoring of DNS queries to known C2 domains via threat intelligence feeds is essential.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.