logo

APT41__2015__Novetta_winntianalysis_04-07-2015.pdf

ID: 9985f61b-7292-4c55-876b-0b2474a85dd8

STIX ID: report--9985f61b-7292-4c55-876b-0b2474a85dd8

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2015-04-06

Last Modified Date: 2015-04-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Novetta report analyzes Winnti v3.0 samples observed in Axiom-related compromises, documenting the multi-stage dropper/service/engine/worker architecture, C2 protocols (custom TCP, HTTP, HTTPS), plugin-based RAT capabilities, robust persistence and update mechanisms, evasion techniques (manual in-memory loading, encrypted payloads, UAC bypass), and provides detection guidance including file/registry indicators and YARA signatures.