Winnti for Windows has the ability to encrypt and compress its payload.6
tool
Winnti for Windows S0141
- Type
- malware
- Platform
- Windows
- Created
- 31 May 2017
- Last modified
- 10 April 2024
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.[1][2][3][4]. The Linux variant is tracked separately under Winnti for Linux.[5]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0141
Winnti for Windows has the ability to encrypt and compress its payload.7
A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.8
Winnti for Windows can check if the explorer.exe process is responsible for calling its install function.9
Winnti for Windows can delete the DLLs for its various components from a compromised host.10
Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe.11
Standing S0141
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
84th percentile · 84% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
53rd percentile · 53% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
56th percentile · 56% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S0141
677 distinct rules cover the 22 techniques recorded for this tool. The 706 technique-to-rule mappings resolve to 677 distinct rules, because one rule can cover several techniques. 497 Sigma · 180 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org