Also known as: Blackfly, Wicked Panda, APT41, Winnti Umbrella, BARIUM, LEAD, TG-2633, BRONZE ATLAS, Earth Freybug, Axiom, Dragonbridge, tracked as, APT 41, Double Dragon, Grayfly, WICKED, Winnti, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Pawn Storm, Fancy Bear, Sednit, STRONTIUM, ADC, Cisco routers, Zoho ManageEngine Desktop Central, APT39, targeting air transportation, government organizations in Kuwait, Saudi Arabia, likely for data exploration, Subaat, LoneRanger, Karma Panda, Taiwan, the US, China, APT10, Stone Panda, Cloud Hopper, Storm 1376, Remix Kitten, Tonto Team, BlackTech
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting.(Citation: Kaspersky Winnti April 2013)(Citation: Kaspersky Winnti June 2015)(Citation: Novetta Winnti April 2015) Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.(Citation: 401 TRG Winnti Umbrella May 2018)
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
Bayer Cyber Attack
No observed data linked yet.
43
Techniques
52
Tools
1
Campaigns
158
IOCs
0
Observed Data
14
Tactics