Detecting threat actors in recent German industrial attacks with Windows Defender ATP – Microsoft Secure
ID: 4b6688a3-3b61-4c40-929b-69f58eb52cc8
STIX ID: report--4b6688a3-3b61-4c40-929b-69f58eb52cc8
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2018-09-10
Last Modified Date: 2018-09-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Microsoft Secure blog describes the Winnti malware implant and two activity groups (BARIUM and LEAD) that have used it for persistent access and industrial espionage, summarizes observed victim types and intrusion methods, provides IOCs and TTPs (e.g., malicious DLLs, rundll32 loading, registry persistence, file locations and hashes), and demonstrates how Windows Defender ATP detects, presents contextual telemetry, and enables response options such as machine isolation and enterprise-wide file blocking.
