APT41__2020__No_Game_over_for_the_Winnti_Group_WeLiveSecurity.pdf
ID: 56f914d1-006e-43bb-845a-5dce712dcd13
STIX ID: report--56f914d1-006e-43bb-845a-5dce712dcd13
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-05-21
Last Modified Date: 2020-05-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes the discovery of PipeMon, a modular backdoor attributed to the Winnti Group that targeted MMO video game developers in South Korea and Taiwan; the malware persists via malicious Windows Print Processor DLLs, uses named-pipe inter-module communication and encrypted modules (stored on disk or in registry), is signed with a likely stolen code-signing certificate, and was used in at least one incident involving compromise of a build system with supply-chain implications. The report includes a full technical breakdown, IOCs (hashes, filenames, registry keys, C2 domains/IPs, named pipes), and MITRE ATT&CK mappings.
