s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.winnti

📛 Threat Title

Malware family: Winnti

Category: Winnti First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.winnti`. Printable name: Winnti.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.winnti VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.winnti

IOC database

Type
domain
Value
elf.winnti
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.winnti

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.winnti

References (1)

Remediations (10)

  • web:attack.mitre.org

    Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. [1] [2] [3] Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group. [4]

  • web:cyber-kill-chain.ch

    Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. [1] [2] [3] Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group. [4]

  • web:cyberpress.org

    The Winnti malware arsenal deployment starts with Winnti SpiderLoader execution via RunDLL32, and then Winnti Stashlog is dropped and uses reflective DLL injection to run, where an attacker retrieves the machine's GUID to identify the victim. According to AttackIQ, Winnti Privatelog is deployed next and utilizes DLL side-loading for execution.

  • web:hivepro.com

    Attack: In March 2024, a sophisticated cyber-attack campaign, dubbed RevivalStone, targeted Japanese companies, marking another high-profile operation by the notorious China-based Winnti Group. Leveraging advanced malware and stealthy intrusion techniques, the attackers infiltrated corporate networks, expanding their reach through interconnected systems and leaving a trail of compromised ...

  • web:hunt.io

    Winnti is an advanced malware family that has been around since at least 2010, targeting Windows systems. It's a modular remote access trojan (RAT) that gives the attacker unauthorized access and control of the compromised device. Winnti has been linked to various Chinese threat actors including APT41 and has been used in cyber espionage campaigns against gaming, healthcare, telecom and tech ...

  • web:risky.biz

    Thanks largely to inconsistent methodologies, poor clustering, and lack of collaboration, the word 'Winnti' has gradually been rendered meaningless. We first heard the word 'Winnti' used to describe some specific attributes or actions: a malware family , stolen code signing certificates, rootkits, malware associated with suspected Chinese hacking, links to some specific Chinese personas ...

  • web:thehackernews.com

    Winnti's RevivalStone campaign exploited an ERP SQL flaw to deploy upgraded malware , breaching an MSP and infecting multiple firms.

  • web:www.bleepingcomputer.com

    The Chinese 'Winnti' hacking group was found using a previously undocumented malware called UNAPIMON to let malicous processes run without being detected.

  • web:www.cybereason.com

    In part one of this research, the Cybereason Nocturnus Incident Response Team provided a unique glimpse into the Winnti intrusion playbook, covering the techniques that were used by the group from initial compromise to stealing the data, as observed and analyzed by the Cybereason Incident Response team. This part of the research zeroes in on the Winnti malware arsenal that was discovered ...

  • web:www.microsoft.com

    Winnti is a family of multi-component malware that give threat actors persistent access and control over infected devices through a backdoor. It has known associations with activity groups involved in cyberespionage.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.