Winnti Malware: A Deep Dive into a Deeper Threat

Download this White Paper

Get instant access to download this white paper with a free Infosecurity Magazine account. Earn CPE credits on qualifying content and explore our full range of webinars, whitepapers, and feature articles, all in one place!

Brought to you by

This event is brought to you by Chronicle Security. By downloading this event, you agree that your details will be shared with Chronicle Security who may contact you in relation to similar products and services which may be of interest. You can read more in Chronicle Security’s Privacy Policy, including how to unsubscribe.

The Winnti malware family was first reported in 2013 by Kaspersky Lab. Since then, threat actors leveraging Winnti malware have victimized a diverse set of targets for varied motivations.

The underlying hypothesis is that the malware itself may be shared (or sold) across a small group of actors. Clusters of Winnti-related activity have become a complex topic in threat intelligence circles, with activity vaguely attributed to different codenamed threat actors.

This whitepaper provides a technical analysis of a small cluster of Winnti samples designed specifically for Linux.