Winnti APT group docks in Sri Lanka for new campaign - Malwarebytes Threat Intelligence Report
ID: 5be70aec-b6e1-461c-8b59-e5b801959e35
STIX ID: report--5be70aec-b6e1-461c-8b59-e5b801959e35
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes Threat Intelligence documents a multi-stage Winnti (APT41) campaign active in August that targeted Sri Lankan government entities via a lured ISO ('economic assistance.iso'). The attack used signed legitimate executables for DLL sideloading to run a malicious DLL (DBoxAgent) that communicates with Dropbox as C2 to exfiltrate data and drop additional components (SerialVlogger, vlog.ipdb) which decrypt and load a KeyPlug backdoor providing remote control via WebSockets; the report includes technical analysis, multiple decoding routines, and IOCs.
