Netskope Threat Labs

Winnti

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Winnti is malware associated with Chinese state sponsored groups that has targeted gaming, technology, and other industries for espionage and financial gain since the late 2000s. Its backdoor provides remote access and module loading, and the group behind it pioneered supply chain compromises that planted implants in legitimate software. Several distinct crews operate under the Winnti umbrella, and its tooling continues to surface in new campaigns.

First seen
February 2022
Last seen
October 2026
WinNti
Alert Name
Backdoor.Winnti.A
Backdoor.Winnti.M
Document-CHM.Backdoor.Winnti
Document-CHM.Trojan.WinNti
Gen:Variant.Linux.Winnti.1
Gen:Variant.Trojan.Linux.Winnti.1
Linux.Backdoor.Winnti
Linux.Backdoor.WinNti
Linux.Trojan.WinNti
Shortcut.Trojan.WinNti