APT41__2021__the-operations-of-winnti-group.pdf
ID: a8a9daba-b8af-4719-a3f4-4b46cdc3c5b9
STIX ID: report--a8a9daba-b8af-4719-a3f4-4b46cdc3c5b9
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2021-05-10
Last Modified Date: 2021-05-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NTT Threat Detection documents Winnti Group (ENT-1) as a full-time, well-resourced APT active from Dec 2020–Apr 2021 targeting multiple countries and sectors across the Asia-Pacific region; the report details exploitation of GlassFish servers to host CobaltStrike and scanning infrastructure (Acunitex), use of Shadowpad/Spyder/Winnti backdoors and a custom CobaltStrike stager (“Fishmaster”), and supplies IPs, domains, and file hashes to support detection and response.
