ATT&CKReferencesChronicle Winnti for Linux May 2019

Chronicle Winnti for Linux May 2019

Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareWinnti for Linux

Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity.

T1027.013
Encrypted/Encoded File
MalwareWinnti for Linux

Winnti for Linux can encode its configuration file with single-byte XOR encoding.

T1071.001
Web Protocols
MalwareWinnti for Linux

Winnti for Linux has used HTTP in outbound communications.

T1095
Non-Application Layer Protocol
MalwareWinnti for Linux

Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications.

T1105
Ingress Tool Transfer
MalwareWinnti for Linux

Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host.

T1140
Deobfuscate/Decode Files or Information
MalwareWinnti for Linux

Winnti for Linux has decoded XOR encoded strings holding its configuration upon execution.

T1205
Traffic Signaling
MalwareWinnti for Linux

Winnti for Linux has used a passive listener, capable of identifying a specific magic value before executing tasking, as a secondary command and control (C2) mechanism.

T1573.001
Symmetric Cryptography
MalwareWinnti for Linux

Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.