Winnti: ESET's research team analyzed a sample of a new backdoor, which its creators have named skip-2.0.
As recently discovered, the backdoor has been added to the arsenal of the notorious cyberespionage group Winnti. Specifically, skip-2.0 attacks MSSQL Server 11 and 12, allowing attackers to log in to any MSSQL account with a special password, automatically hiding these connections from the logs. 
Such a backdoor could allow an attacker to copy, modify, or delete content from databases. This capability could be used, for example, to abuse in-game currencies for financial gain.
It is known that in the past, cybercriminals from the Winnti group have been involved in malicious actions related to in-game currency databases.
"This backdoor allows the attacker to remain persistent within the victim's MSSQL server through the use of a special password, and, at the same time, invisible, thanks to the multiple log and event publishing mechanisms, which are disabled when this password is used," explains ESET researcher Mathieu Tartare, who participated in the research for the Winnti team.
We tested skip-2.0 on several versions of MSSQL Server and found that we could successfully connect using the special password only with MSSQL Server 11 and 12. Although MSSQL Server 11 and 12 are not the latest versions, they are the most common,” adds Tartare.
ESET has observed many similarities between skip-2.0 and other known tools from the Winnti team’s arsenal, such as a VMPprotected launcher, its custom packer, and an Inner-Loader injector that use the same hooking process. “Because of this, we conclude that skip-2.0 also belongs to this toolkit.
.
ESET researchers have been monitoring Winnti's activities for some time. The group has been active since at least 2012 and is responsible for high-profile supply-chain attacks against the video game and software industries. ESET recently published a white paper with more information about the Winnti group's arsenal and for the first time reveals a backdoor called PortReuse.
More technical details can be found in the article "Winnti Group's skip-2.0: a Microsoft SQL Server backdoor" regarding the functionality of this backdoor, as well as its similarities to the Winnti Group's well-known arsenal – specifically the PortReuse and ShadowPad backdoors.
