WINTAPIX: New Kernel Driver Targets Middle Eastern Countries
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation,Backdoor,Rootkit
- Attack Complexity: High
- Threat Risk: High Impact/High Probability
Threat Overview
Fortinet researchers discovered WINTAPIX, a sophisticated Windows kernel driver suspected to be the work of Iranian threat actors, targeting IIS web servers across the Middle East — primarily in Saudi Arabia, with additional targeting of Jordan, Qatar, and the United Arab Emirates. Active since at least mid-2020, the malware remained largely undetected for years before significant spikes in activity emerged in August–September 2022 and February–March 2023. WINTAPIX operates at the kernel level, giving it deep system access and making it significantly harder to detect and remove than user-mode implants. The driver uses the open-source Donut framework to generate and inject shellcode that loads an obfuscated .NET payload into a target process. The payload — protected with SmartAssembly and Eazfuscator to resist reverse engineering — provides the operators with backdoor access and proxy functionality, enabling persistent remote control and traffic tunneling through the compromised IIS server. The driver itself is shielded with VMProtect, transforming its code into a virtualized format to hinder static analysis.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Jordan | Verified |
| Region | Qatar | Verified |
| Region | Saudi Arabia | Verified |
| Region | United Arab Emirates | Verified |
Extracted IOCs
- 1485c0ed3e875cbdfc6786a5bd26d18ea9d31727deb8df290a1c00c780419a4e
- 27a6c3f5c50c8813ca34ab3b0791c08817c803877665774954890884842973ed
- 8578bff36e3b02cc71495b647db88c67c3c5ca710b5a2bd539148550595d0330
- aae9c8bd9db4e0d48e35d9ab3b1a8c7933284dcbeb344809fed18349a9ec7407
- f6c316e2385f2694d47e936b0ac4bc9b55e279d530dd5e805f0d963cb47c3c0d
Tip: 5 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 5 file hash) to this threat have been found.
Overlaps
Source: darksys0x - June 2023
Detection (one case): f6c316e2385f2694d47e936b0ac4bc9b55e279d530dd5e805f0d963cb47c3c0d
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About WINTAPIX and Its Targeting of Middle Eastern IIS Servers
Fortinet researchers discovered a sophisticated Windows kernel driver called WINTAPIX, suspected to be developed by Iranian threat actors, that has been targeting Internet Information Services (IIS) web servers in Saudi Arabia, Jordan, Qatar, and the United Arab Emirates since at least mid-2020. The malware went largely undetected for years before activity spikes in 2022 and 2023 prompted investigation. WINTAPIX installs itself at the kernel level and uses the Donut shellcode framework to inject an obfuscated .NET backdoor into IIS server processes, giving the operators persistent remote access and traffic proxying capabilities.
Fortinet attributes WINTAPIX to Iranian threat actors based on the targeting profile and tooling. Attribution has since evolved: some security sources link the activity to the Agrius group, while a November 2023 Check Point report on Scarred Manticore references WINTAPIX as part of that actor's broader IIS-targeting campaign across the Middle East. The exact group responsible has not been definitively confirmed, but Iranian state involvement is consistently assessed across multiple sources.
WINTAPIX is designed for long-term espionage and intelligence collection. Its backdoor functionality gives operators persistent access to compromised IIS servers — enabling them to monitor traffic, execute commands, exfiltrate data, and tunnel network communications through the infected server. The proxy capability in particular suggests the operators may also use compromised servers as relay infrastructure for other operations, consistent with Iranian state espionage priorities in the Gulf region.
The campaign has been active since at least mid-2020, making it a multi-year operation spanning over three years. Targeting is concentrated in four Middle Eastern countries: Saudi Arabia (the primary target), Jordan, Qatar, and the United Arab Emirates. The consistent focus on Gulf states aligns with Iranian geopolitical interests in monitoring regional rivals and adversaries. Activity spikes in 2022 and 2023 suggest the campaign remains active and ongoing rather than a historical operation.
WINTAPIX specifically targets organizations running Microsoft IIS web servers, which are commonly deployed by government agencies, enterprises, and critical infrastructure operators in the region. Given the four countries targeted and the state-sponsored nature of the campaign, government entities, public sector organizations, and large enterprises with IIS-hosted web applications are at highest risk. Any organization running IIS infrastructure in Saudi Arabia, Jordan, Qatar, or the UAE should consider themselves a potential target.
WINTAPIX gains access through IIS servers and installs itself as a Windows kernel-mode driver, registering as a service via registry modifications to ensure it runs on every system boot. The driver uses the open-source Donut framework to generate shellcode, which is injected into a running IIS worker process. This shellcode then loads an obfuscated .NET payload in memory — protected by SmartAssembly and Eazfuscator to resist analysis. The driver itself is shielded with VMProtect, which converts its code into a virtualized format to defeat reverse engineering. Together, these layers give the operators a deeply embedded, hard-to-detect implant with full backdoor and proxy functionality.
IIS servers are attractive targets because they are often internet-facing, handle sensitive web traffic, and run with elevated privileges on Windows systems. In the Gulf region, IIS is widely used by government portals, enterprise web applications, and critical infrastructure operators — making compromised IIS servers valuable both for intelligence collection and as relay nodes for further operations. The kernel-level persistence WINTAPIX achieves on IIS hosts gives operators long-term, difficult-to-evict access to high-value targets.
Deploy endpoint detection with kernel-level visibility — user-mode security tools are insufficient against a kernel driver implant. Monitor IIS servers specifically for unauthorized driver installations, new service registrations, and unexpected registry modifications at boot. Patch IIS and Windows regularly to close the vulnerabilities WINTAPIX exploits for initial access. Hunt proactively for the known WINTAPIX file hashes and check for overlap with SRVNET2 indicators. Restrict RDP and remote service access to IIS servers to limit lateral movement if a compromise occurs. Organizations in Saudi Arabia, Jordan, Qatar, and the UAE running IIS infrastructure should treat this as an active threat and audit their environments accordingly.