logo

APT41__2020__No_Game_over_for_the_Winnti_Group_WeLiveSecurity.pdf

ID: 56f914d1-006e-43bb-845a-5dce712dcd13

STIX ID: report--56f914d1-006e-43bb-845a-5dce712dcd13

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2020-05-21

Last Modified Date: 2020-05-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes the discovery of PipeMon, a modular backdoor attributed to the Winnti Group that targeted MMO video game developers in South Korea and Taiwan; the malware persists via malicious Windows Print Processor DLLs, uses named-pipe inter-module communication and encrypted modules (stored on disk or in registry), is signed with a likely stolen code-signing certificate, and was used in at least one incident involving compromise of a build system with supply-chain implications. The report includes a full technical breakdown, IOCs (hashes, filenames, registry keys, C2 domains/IPs, named pipes), and MITRE ATT&CK mappings.