Winnti
Actor Type | Nation State |
---|---|
Attributed to Nation | China |
Affiliated Intrusion Sets | Wicked Panda , SparklingGoblin |
Associated Threat Actor | Chengdu 404 |
Associated MITRE ATT&CK Group | Winnti Group (G0044) |
Over time, Winnti (also known as Winnti Group) has become an umbrella term which likely covers multiple overlapping threat groups linked to the People's Republic of China (PRC). The name comes from a specific piece of malware dubbed 'Winnti'.
The group has been linked to APT41, Wicked Panda, Wicked Spider, Blackfly and BARIUM. It has been linked to the Chinese company Chengdu 404 by the US government.
The Winnti Group has been reported as an elusive Chinese state-sponsored Advanced Persistent Threat (APT) group. Their activities span cyber espionage and cyber crime, with a focus on stealing sensitive technology-related information.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
Winnti Threat Reports
The Operations of Winnti group
This report from researchers at NTT describes activity which they attribute to the Winnti Group (who they refer to as ENT-1) and identify overlaps ...