Winnti Group
Also reported as Blackfly.
Reports per quarter
Techniques seen in the last two years
- T1003.001 4 reports reports only
- T1543.003 4 reports reports only
- T1016 3 reports reports only
- T1057 3 reports in ATT&CK
- T1059.003 3 reports reports only
- T1071.001 3 reports reports only
- T1087.001 3 reports reports only
- T1095 3 reports reports only
- T1140 3 reports reports only
- T1547.001 3 reports reports only
Show all 86 techniques Show fewer
- T1555.003 3 reports reports only
- T1569.002 3 reports reports only
- T1003.002 2 reports reports only
- T1021.002 2 reports reports only
- T1027.002 2 reports reports only
- T1053.002 2 reports reports only
- T1053.005 2 reports reports only
- T1055 2 reports reports only
- T1056.001 2 reports reports only
- T1059.001 2 reports reports only
- T1069.002 2 reports reports only
- T1071.004 2 reports reports only
- T1082 2 reports reports only
- T1087.002 2 reports reports only
- T1090.001 2 reports reports only
- T1105 2 reports in ATT&CK
- T1560.001 2 reports reports only
- T1564.001 2 reports reports only
- T1566.001 2 reports reports only
- T1003.003 1 report reports only
- T1005 1 report reports only
- T1007 1 report reports only
- T1008 1 report reports only
- T1012 1 report reports only
- T1018 1 report reports only
- T1027 1 report reports only
- T1027.001 1 report reports only
- T1033 1 report reports only
- T1036.004 1 report reports only
- T1036.005 1 report reports only
- T1037 1 report reports only
- T1040 1 report reports only
- T1041 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
- T1049 1 report reports only
- T1055.001 1 report reports only
- T1059.005 1 report reports only
- T1068 1 report reports only
- T1069 1 report reports only
- T1070.004 1 report reports only
- T1072 1 report reports only
- T1078.002 1 report reports only
- T1083 1 report in ATT&CK
- T1087 1 report reports only
- T1106 1 report reports only
- T1112 1 report reports only
- T1113 1 report reports only
- T1119 1 report reports only
- T1124 1 report reports only
- T1132.001 1 report reports only
- T1135 1 report reports only
- T1190 1 report reports only
- T1197 1 report reports only
- T1204.002 1 report reports only
- T1218.011 1 report reports only
- T1222 1 report reports only
- T1482 1 report reports only
- T1546.015 1 report reports only
- T1548.002 1 report reports only
- T1550.002 1 report reports only
- T1552.001 1 report reports only
- T1553.002 1 report in ATT&CK
- T1555 1 report reports only
- T1556.002 1 report reports only
- T1566.002 1 report reports only
- T1570 1 report reports only
- T1571 1 report reports only
- T1572 1 report reports only
- T1573.001 1 report reports only
- T1583.001 1 report in ATT&CK
- T1583.004 1 report reports only
- T1596.005 1 report reports only
- T1602 1 report reports only
- T1614.001 1 report reports only
- T1620 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
Show all 171 CVEs Show fewer
- CVE-2012-1889 KEV
- CVE-2012-5687
- CVE-2013-0640 KEV
- CVE-2013-0707
- CVE-2013-1347 KEV
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3906 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2013-7389
- CVE-2014-0322 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4404 KEV
- CVE-2014-6324 KEV
- CVE-2014-6332 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2051 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-8651 KEV
- CVE-2016-0099 KEV ransomware
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-0545
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-7836 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6190
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-16098
- CVE-2019-17100
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2019-948919
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-1664
- CVE-2020-35730 KEV
- CVE-2020-3702
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2020-846820
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-24085
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-30657 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-34527 KEV ransomware
- CVE-2021-36942 KEV ransomware
- CVE-2021-38001
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-40444 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-0847 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-39952
- CVE-2022-40684 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-49475
- CVE-2023-27350 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-21413 KEV
- CVE-2024-30051 KEV ransomware
- CVE-2024-4577 KEV ransomware
- CVE-2025-0411 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ISFB (Malware Family)
-
Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gandcrab (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Crimson RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor RagnarLocker (Malware Family)
Show all 293 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
ShadowPad: new activity from the Winnti group
The original link failed its last check. Original publisher Detailsfor ShadowPad: new activity from the Winnti group
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ave Maria (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DanaBot (Malware Family)
-
BazarBackdoor (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BazarBackdoor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Clop (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SmokeLoader (Malware Family)
-
APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WastedLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ZXShell (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Egregor (Malware Family)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor i-soon-data-leaks-jp
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor i-soon-data-leaks-en
-
Mélofée- a new alien malware in the Panda's toolset targeting Linux hosts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mélofée- a new alien malware in the Panda's toolset targeting Linux hosts
-
Blackfly: Espionage Group Targets Materials Technology
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Blackfly: Espionage Group Targets Materials Technology
-
Update to the REF2924 intrusion set and related campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update to the REF2924 intrusion set and related campaigns
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
APT41 World Tour 2021 on a tight schedule
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41 World Tour 2021 on a tight schedule
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41- A Case Sudy
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
Operation CuckooBees- Deep-Dive into Stealthy Winnti Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation CuckooBees- Deep-Dive into Stealthy Winnti Techniques
-
Operation CuckooBees- A Winnti Malware Arsenal Deep-Dive
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation CuckooBees- A Winnti Malware Arsenal Deep-Dive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamer Cheater Hacker Spy
-
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits
-
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
-
New Milestones for Deep Panda- Log4Shell and Digitally Signed Fire Chili Rootkits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Milestones for Deep Panda- Log4Shell and Digitally Signed Fire Chili Rootkits
-
New Milestones for Deep Panda_ Log4Shell and Digitally Signed Fire Chili Rootkits
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Milestones for Deep Panda_ Log4Shell and Digitally Signed Fire Chili Rootkits
-
Delving Deep: An Analysis of Earth Lusca's Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Delving Deep: An Analysis of Earth Lusca's Operations
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Winnti is Coming - Evolution after Prosecution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
Operation ‘Harvest’_ A Deep Dive into a Long-term Campaign _ McAfee Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ‘Harvest’_ A Deep Dive into a Long-term Campaign _ McAfee Blogs
-
Operation ‘Harvest’- A Deep Dive into a Long-term Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation ‘Harvest’- A Deep Dive into a Long-term Campaign
-
Grayfly- Chinese Threat Actor Uses Newly-discovered Sidewalk Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Grayfly- Chinese Threat Actor Uses Newly-discovered Sidewalk Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2021ThreatHunting
-
Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Earth Baku: An APT Group Targeting Indo-Pacific Countries With New Stealth Loaders and Backdoor
-
The SideWalk may be as dangerous as the CROSSWALK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The SideWalk may be as dangerous as the CROSSWALK
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shadowpad
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
BIOPASS RAT New Malware Sniffs Victims via Live Streaming
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BIOPASS RAT New Malware Sniffs Victims via Live Streaming
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
BIOPASS RAT- New Malware Sniffs Victims via Live Streaming
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BIOPASS RAT- New Malware Sniffs Victims via Live Streaming
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
China’s “Winnti” Spyder Module
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China’s “Winnti” Spyder Module
-
New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor
-
Linux Backdoor RedXOR Likely Operated by Chinese Nation-State
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Linux Backdoor RedXOR Likely Operated by Chinese Nation-State
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
Microsoft Exchange Zero Days - Mitigations and Detections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange Zero Days - Mitigations and Detections
-
Threat Attribution — Chimera -Under the Radar-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Attribution — Chimera -Under the Radar-
-
Emulation of Kernel Mode Rootkits With Speakeasy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emulation of Kernel Mode Rootkits With Speakeasy
-
ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new
-
Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti- APT41 backdoors, old and new
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Higaisa or Winnti- APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT27+turns+to+ransomware
-
China's APT hackers move to ransomware attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China's APT hackers move to ransomware attacks
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
MosaicRegressor- Lurking in the Shadows of UEFI
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MosaicRegressor- Lurking in the Shadows of UEFI
-
APT41- Indictments Put Chinese Espionage Group in the Spotlight
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT41- Indictments Put Chinese Espionage Group in the Spotlight
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
2020.09.29_ShadowPad - new activity from the Winnti group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.09.29_ShadowPad - new activity from the Winnti group
-
Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What even is Winnti-
-
ELF Malware Analysis 101- Linux Threats No Longer an Afterthought
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ELF Malware Analysis 101- Linux Threats No Longer an Afterthought
-
No “Game over” for the Winnti Group _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor No “Game over” for the Winnti Group _ WeLiveSecurity
-
No “Game over” for the Winnti Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor No “Game over” for the Winnti Group
-
Shadows with a chance of BlackNix
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shadows with a chance of BlackNix
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q12020
-
WINNTI GROUP_ Insights From the Past
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP_ Insights From the Past
-
WINNTI GROUP- Insights From the Past
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WINNTI GROUP- Insights From the Past
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report-bb-decade-of-the-rats
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shadows in the Rain
-
GitHub Repository- winnti-sniff
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GitHub Repository- winnti-sniff
-
Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
-
Uncovering DRBControl- Inside the Cyberespionage Campaign Targeting Gambling Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering DRBControl- Inside the Cyberespionage Campaign Targeting Gambling Operations
-
Winnti Group targeting universities in Hong Kong
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group targeting universities in Hong Kong
-
Winnti Group targeting universities in Hong Kong
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group targeting universities in Hong Kong
-
Deutsches Chemieunternehmen gehackt
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deutsches Chemieunternehmen gehackt
-
The malware analyst’s guide to PE timestamps
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The malware analyst’s guide to PE timestamps
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 01/2019
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
APT cases exploiting vulnerabilities in region‑specific software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT cases exploiting vulnerabilities in region‑specific software
-
The original link failed its last check. Original publisher Detailsfor mobile-malware-report.pdf
-
Winnti Group’s skip‑2.0_ A Microsoft SQL Server backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group’s skip‑2.0_ A Microsoft SQL Server backdoor
-
Winnti Group’s skip‑2.0- A Microsoft SQL Server backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Group’s skip‑2.0- A Microsoft SQL Server backdoor
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Winnti
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti_ Attack or Scan
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti- Attack or Scan-
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
TLP-WHITE-CERT-EU-MEMO-190725-1.pdf
The original link failed its last check. Original publisher Detailsfor TLP-WHITE-CERT-EU-MEMO-190725-1.pdf
-
Attacking the Heart of the German Industry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacking the Heart of the German Industry
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti analysis
-
Winnti_ Attacking the Heart of the German Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti_ Attacking the Heart of the German Industry
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
HiddenWasp Malware Stings Targeted Linux Systems
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HiddenWasp Malware Stings Targeted Linux Systems
-
HiddenWasp Malware Stings Targeted Linux Systems
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HiddenWasp Malware Stings Targeted Linux Systems
-
TeamViewer Confirms Undisclosed Breach From 2016
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TeamViewer Confirms Undisclosed Breach From 2016
-
Winnti_ More than just Windows and Gates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti_ More than just Windows and Gates
-
Bayer points finger at Wicked Panda in cyberattack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bayer points finger at Wicked Panda in cyberattack
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
Gaming industry still in the scope of attackers in Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gaming industry still in the scope of attackers in Asia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gaming-Industry.Asia
-
Meet CrowdStrike’s Adversary of the Month for July- WICKED SPIDER
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for July- WICKED SPIDER
-
Nmap Script to scan for Winnti infections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nmap Script to scan for Winnti infections
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Burning Umbrella
-
Suricata rules to detect Winnti communication
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suricata rules to detect Winnti communication
-
An intrusion campaign targeting Chinese language news sites
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor An intrusion campaign targeting Chinese language news sites
-
Recent Winnti Infrastructure and Samples _ ClearSky Cybersecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Recent Winnti Infrastructure and Samples _ ClearSky Cybersecurity
-
Winnti Evolution - Going Open Source
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Evolution - Going Open Source
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Insider_Information
-
Examining a Possible Member of the Winnti Group
The original link failed its last check. Original publisher Detailsfor Examining a Possible Member of the Winnti Group
-
Of Pigs and Malware- Examining a Possible Member of the Winnti Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Of Pigs and Malware- Examining a Possible Member of the Winnti Group
-
Winnti Abuses GitHub for C&C Communications
The original link failed its last check. Original publisher Detailsfor Winnti Abuses GitHub for C&C Communications
-
Winnti Abuses GitHub for C&C Communications
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti Abuses GitHub for C&C Communications
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting threat actors in recent German industrial attacks with Windows Defender ATP – Microsoft Secure
-
Detecting threat actors in recent German industrial attacks with Windows Defender ATP
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting threat actors in recent German industrial attacks with Windows Defender ATP
-
Digitally Signed Malware Targeting Gaming Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digitally Signed Malware Targeting Gaming Companies
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Universal Windows Bootkit
-
Suckfly: Revealing the secret life of your code signing certificates
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Suckfly: Revealing the secret life of your code signing certificates
-
Suckfly: Revealing the secret life of your code signing certificates | Symantec Connect Community
The link to CyberMonitor archive on GitHub failed its last check. CyberMonitor archive on GitHub Detailsfor Suckfly: Revealing the secret life of your code signing certificates | Symantec Connect Community
-
Suckfly- Revealing the secret life of your code signing certificates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Suckfly- Revealing the secret life of your code signing certificates
-
Network detector for Winnti malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Network detector for Winnti malware
-
Evolution of Cyber Threats in the Corporate Sector
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Evolution of Cyber Threats in the Corporate Sector
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor I am HDRoot! Part 2
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor I am HDRoot! Part 1
-
Games are over- Winnti is now targeting pharmaceutical companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Games are over- Winnti is now targeting pharmaceutical companies
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Games are over - Securelist
-
The link to Mirror on Box failed its last check. Detailsfor WINNTI Analysis
-
The original link failed its last check. Original publisher Detailsfor WINNTI Analysis
-
Backdoor.Winnti attackers have a skeleton in their closet?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Backdoor.Winnti attackers have a skeleton in their closet?
-
Threat Group-3279 Targets the Video Game Industry | Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group-3279 Targets the Video Game Industry | Secureworks
-
Winnti FAQ. More Than Just a Game
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti FAQ. More Than Just a Game
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti. More than just a game
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Kaspersky Lab
Newest first. Details opens the report in Explore.