logo

APT41__2020__WINNTI_GROUP_Insights_From_the_Past.pdf

ID: 9740eaf7-38f2-43c9-a9ce-0e5ec5de7a56

STIX ID: report--9740eaf7-38f2-43c9-a9ce-0e5ec5de7a56

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2020-04-21

Last Modified Date: 2020-04-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This intelligence report details Winnti Group (APT41) activity: analysis of 2014–2016-era malware and drivers (including signed rootkits and DSE bypass tools), discovery of a previously undocumented DNS-tunneling C2 channel implemented via embedded iodine, and targeting of a German chemical company and a South Korean game firm; the report includes numerous IoCs (hashes, domains, IPs), technical analysis of binaries and C2 behavior, and MITRE ATT&CK mappings with recommended defensive actions.