APT41__2019__HELO_Winnti_Attack_or_Scan.pdf
ID: 860c7bfc-922c-441b-b810-1aa68e9812f0
STIX ID: report--860c7bfc-922c-441b-b810-1aa68e9812f0
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2019-10-01
Last Modified Date: 2019-10-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Lastline analysis examines the Winnti toolkit (a long‑running, sophisticated RAT used by multiple APT actors), documents a July–August 2019 surge in Winnti HELO network activity driven largely by benign scanners, shows how that scan noise buries true infections in telemetry, and provides diagnostic/triage techniques (application‑layer response inspection, HELO generation analysis, and fixes to scanner randomness) and recommendations to reduce false alerts.
