Winnti Group — APT Profile
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Blackfly
IntelFusions coverage (1)
- Winnti Group Targets Hong Kong Universities with ShadowPad: HP Digital Imaging DLL Sideloading, Parent Process Patching, and 17-Module Backdoor with University Campaign IDs 2026-02-16 · Nation-State
Tools & malware
- PipeMon Backdoor
- PlugX Backdoor
- PortReuse malware
- ShadowPad malware
- skip-2.0 malware
- Winnti for Windows Backdoor
Vendor research
- ESET (WeLiveSecurity) ESET
- Suckfly: Revealing the secret life of your code signing certificates Symantec
- Burning Umbrella: An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers 401 TRG
- Winnti. More than just a game Kaspersky
- Winnti Analysis Novetta
- Games are over: Winnti is now targeting pharmaceutical companies Kaspersky
Countries linked to this actor
- South Korea targets
- Taiwan targets
- Sri Lanka targets