Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Winnti Group

Also known as: Blackfly, Wicked Panda, APT41, Winnti Umbrella, BARIUM, LEAD, TG-2633, BRONZE ATLAS, Earth Freybug, Axiom, Dragonbridge, tracked as, APT 41, Double Dragon, Grayfly, WICKED, Winnti, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Pawn Storm, Fancy Bear, Sednit, STRONTIUM, ADC, Cisco routers, Zoho ManageEngine Desktop Central, APT39, targeting air transportation, government organizations in Kuwait, Saudi Arabia, likely for data exploration, Subaat, LoneRanger, Karma Panda, Taiwan, the US, China, APT10, Stone Panda, Cloud Hopper, Storm 1376, Remix Kitten, Tonto Team, BlackTech

Description

Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting.(Citation: Kaspersky Winnti April 2013)(Citation: Kaspersky Winnti June 2015)(Citation: Novetta Winnti April 2015) Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.(Citation: 401 TRG Winnti Umbrella May 2018)

Goals & Targeting

Targeted Sectors

Healthcare
Manufacturing
Critical infrastructure
Technology
Media
Gaming
Government
Financial services
Telecommunications
Defense
Education
Pharmaceutical
Energy
Non profit
Aerospace
Critical infrastructure
Aviation
Transportation
Hospitality
Retail
Information technology
Chemical
Mining
Think tank
Utilities
Oil gas
Construction
Maritime
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

CN
US
TW
RU
IR
IL
IN
JP
SA
AE
KR
GB
VN
AU
PK
UA
SG
DE
MX
PL
CA
IT
BY
TR
FR
ES
AZ
RO
NG
KP
LB
KZ

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 Filename 4 SHA-256 Hash 2 IPv4 Address 2

References

  1. Symantec Suckfly March 2016 — DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.
  2. 401 TRG Winnti Umbrella May 2018 — Hegel, T. (2018, May 3). Burning Umbrella: An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers. Retrieved July 8, 2018.
  3. Kaspersky Winnti April 2013 — Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.
  4. Novetta Winnti April 2015 — Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.
  5. Kaspersky Winnti June 2015 — Tarakanov, D. (2015, June 22). Games are over: Winnti is now targeting pharmaceutical companies. Retrieved January 14, 2016.
  6. attack.mitre.org — Cited by web research for: Sandworm Team
  7. ics-cert.kaspersky.com — Cited by web research for: Pawn Storm
  8. attack.mitre.org — Cited by web research for: T1134
  9. apt.etda.or.th — Cited by web research for: Mimikatz
  10. www.recordedfuture.com — Cited by web research for: 139.180.141.227
  11. apt.etda.or.th — Cited by web research for: money.The

Intel Summary

43

Techniques

52

Tools

1

Campaigns

158

IOCs

0

Observed Data

14

Tactics

Tags

APT

Details

MITRE ID
G0044
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 26, 2026
STIX ID
intrusion-set--c5947e1c-1cbc-434c-94b8-27c7e3be0fff
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.