Winnti

Actor Type Nation State
Attributed to Nation China
Affiliated Intrusion Sets Wicked Panda , SparklingGoblin
Associated Threat Actor Chengdu 404
Associated MITRE ATT&CK Group Winnti Group (G0044)

Over time, Winnti (also known as Winnti Group) has become an umbrella term which likely covers multiple overlapping threat groups linked to the People's Republic of China (PRC). The name comes from a specific piece of malware dubbed 'Winnti'.

The group has been linked to APT41, Wicked Panda, Wicked Spider, Blackfly and BARIUM. It has been linked to the Chinese company Chengdu 404 by the US government.

The Winnti Group has been reported as an elusive Chinese state-sponsored Advanced Persistent Threat (APT) group. Their activities span cyber espionage and cyber crime, with a focus on stealing sensitive technology-related information.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Winnti Threat Reports

Report

The Operations of Winnti group

This report from researchers at NTT describes activity which they attribute to the Winnti Group (who they refer to as ENT-1) and identify overlaps ...

References