Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareWinnti for Linux | Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity. |
| T1027.013 Encrypted/Encoded File |
MalwareWinnti for Linux | Winnti for Linux can encode its configuration file with single-byte XOR encoding. |
| T1071.001 Web Protocols |
MalwareWinnti for Linux | Winnti for Linux has used HTTP in outbound communications. |
| T1095 Non-Application Layer Protocol |
MalwareWinnti for Linux | Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications. |
| T1105 Ingress Tool Transfer |
MalwareWinnti for Linux | Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWinnti for Linux | Winnti for Linux has decoded XOR encoded strings holding its configuration upon execution. |
| T1205 Traffic Signaling |
MalwareWinnti for Linux | Winnti for Linux has used a passive listener, capable of identifying a specific magic value before executing tasking, as a secondary command and control (C2) mechanism. |
| T1573.001 Symmetric Cryptography |
MalwareWinnti for Linux | Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.