logo

APT41__2019__HELO_Winnti_Attack_or_Scan.pdf

ID: 860c7bfc-922c-441b-b810-1aa68e9812f0

STIX ID: report--860c7bfc-922c-441b-b810-1aa68e9812f0

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2019-10-01

Last Modified Date: 2019-10-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Lastline analysis examines the Winnti toolkit (a long‑running, sophisticated RAT used by multiple APT actors), documents a July–August 2019 surge in Winnti HELO network activity driven largely by benign scanners, shows how that scan noise buries true infections in telemetry, and provides diagnostic/triage techniques (application‑layer response inspection, HELO generation analysis, and fixes to scanner randomness) and recommendations to reduce false alerts.