APT41__2020__WINNTI_GROUP_Insights_From_the_Past.pdf
ID: 9740eaf7-38f2-43c9-a9ce-0e5ec5de7a56
STIX ID: report--9740eaf7-38f2-43c9-a9ce-0e5ec5de7a56
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-04-21
Last Modified Date: 2020-04-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This intelligence report details Winnti Group (APT41) activity: analysis of 2014–2016-era malware and drivers (including signed rootkits and DSE bypass tools), discovery of a previously undocumented DNS-tunneling C2 channel implemented via embedded iodine, and targeting of a German chemical company and a South Korean game firm; the report includes numerous IoCs (hashes, domains, IPs), technical analysis of binaries and C2 behavior, and MITRE ATT&CK mappings with recommended defensive actions.
