APT41__2019__Winnti_Attacking_the_Heart_of_the_German_Industry.pdf
ID: b45f00fd-bc89-4254-b5b7-a130a36d1639
STIX ID: report--b45f00fd-bc89-4254-b5b7-a130a36d1639
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-07-25
Last Modified Date: 2019-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
An in-depth joint investigation reveals the Winnti group — a persistent, sophisticated malware-enabled actor active since at least 2011 — carried out industrial espionage against numerous German DAX firms and international targets across gaming, chemical, pharma and tech sectors; researchers analyzed hundreds of Winnti malware variants, recovered identifying markers and IOCs, used network scanning to locate infected hosts, and present evidence suggesting links to China-based actors.
