TF-MAL-elf.winnti
📛 Threat Title
Malware family: Winnti
Description
ThreatFox malware family `elf.winnti`. Printable name: Winnti.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.winnti
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.winnti
IOC database
- Type
- domain
- Value
elf.winnti- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.winnti
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.winnti
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. [1] [2] [3] Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group. [4]
-
web:cyber-kill-chain.ch
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. [1] [2] [3] Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group. [4]
-
web:cyberpress.org
The Winnti malware arsenal deployment starts with Winnti SpiderLoader execution via RunDLL32, and then Winnti Stashlog is dropped and uses reflective DLL injection to run, where an attacker retrieves the machine's GUID to identify the victim. According to AttackIQ, Winnti Privatelog is deployed next and utilizes DLL side-loading for execution.
-
web:hivepro.com
Attack: In March 2024, a sophisticated cyber-attack campaign, dubbed RevivalStone, targeted Japanese companies, marking another high-profile operation by the notorious China-based Winnti Group. Leveraging advanced malware and stealthy intrusion techniques, the attackers infiltrated corporate networks, expanding their reach through interconnected systems and leaving a trail of compromised ...
-
web:hunt.io
Winnti is an advanced malware family that has been around since at least 2010, targeting Windows systems. It's a modular remote access trojan (RAT) that gives the attacker unauthorized access and control of the compromised device. Winnti has been linked to various Chinese threat actors including APT41 and has been used in cyber espionage campaigns against gaming, healthcare, telecom and tech ...
-
web:risky.biz
Thanks largely to inconsistent methodologies, poor clustering, and lack of collaboration, the word 'Winnti' has gradually been rendered meaningless. We first heard the word 'Winnti' used to describe some specific attributes or actions: a malware family , stolen code signing certificates, rootkits, malware associated with suspected Chinese hacking, links to some specific Chinese personas ...
-
web:thehackernews.com
Winnti's RevivalStone campaign exploited an ERP SQL flaw to deploy upgraded malware , breaching an MSP and infecting multiple firms.
-
web:www.bleepingcomputer.com
The Chinese 'Winnti' hacking group was found using a previously undocumented malware called UNAPIMON to let malicous processes run without being detected.
-
web:www.cybereason.com
In part one of this research, the Cybereason Nocturnus Incident Response Team provided a unique glimpse into the Winnti intrusion playbook, covering the techniques that were used by the group from initial compromise to stealing the data, as observed and analyzed by the Cybereason Incident Response team. This part of the research zeroes in on the Winnti malware arsenal that was discovered ...
-
web:www.microsoft.com
Winnti is a family of multi-component malware that give threat actors persistent access and control over infected devices through a backdoor. It has known associations with activity groups involved in cyberespionage.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.