Winnti APT group docks in Sri Lanka for new campaign - Malwarebytes Threat Intelligence Report
ID: a8f5d30c-6e64-459d-94df-d4c581163910
STIX ID: report--a8f5d30c-6e64-459d-94df-d4c581163910
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-10-18
Last Modified Date: 2022-10-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes identifies a multi-stage Winnti (APT41) campaign from early August that targeted Sri Lankan government entities using an ISO lure ('economic assistance.iso') which sideloaded a malicious DLL to deploy a Dropbox-based backdoor (DBoxAgent), a second-stage loader (SerialVlogger via signed jcef_helper.exe and libcef.dll), a per-victim encrypted payload (vlog.ipdb) and the KeyPlug backdoor using WebSocket C2; the report includes technical analysis, custom encoding/packing techniques, IOCs, and notes that Dropbox disabled the attacker account.
