The Winnti malware family was first reported in 2013 by Kaspersky Lab. Since then, threat actors leveraging Winnti malware have victimized a diverse set of targets for varied motivations.
The underlying hypothesis is that the malware itself may be shared (or sold) across a small group of actors. In April 2019, reports emerged of an intrusion involving Winnti malware at a German Pharmaceutical company.
Following these reports, Chronicle researchers doubled down on efforts to try to unravel the various campaigns where Winnti was leveraged. Analysis of these larger convoluted clusters is ongoing.
While reviewing a 2015 report of a Winnti intrusion at a Vietnamese gaming company, Chronicle identified a small cluster of Winnti samples designed specifically for Linux.
This white paper is a technical analysis of this variant.