APT41__2019__ESET_Winnti.pdf
ID: b72e931a-a995-4aab-a496-f45407bf04ae
STIX ID: report--b72e931a-a995-4aab-a496-f45407bf04ae
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-10-07
Last Modified Date: 2019-10-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This ESET technical report analyzes the Winnti Group’s toolkit and methods, exposing a novel PortReuse passive network backdoor that injects into processes listening on common ports, updated ShadowPad variants, VMProtected droppers, and custom packing/crypto techniques used in supply-chain compromises; it includes modular architecture details, exploitation and persistence techniques, C2 retrieval mechanisms (public-hosted documents/profiles), extensive IoCs (hashes, IPs, signatures), and evidence of active abuse (Censys-identified infected hosts and Monero miners).
