logo

APT41__2019__ESET_Winnti.pdf

ID: b72e931a-a995-4aab-a496-f45407bf04ae

STIX ID: report--b72e931a-a995-4aab-a496-f45407bf04ae

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-10-07

Last Modified Date: 2019-10-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This ESET technical report analyzes the Winnti Group’s toolkit and methods, exposing a novel PortReuse passive network backdoor that injects into processes listening on common ports, updated ShadowPad variants, VMProtected droppers, and custom packing/crypto techniques used in supply-chain compromises; it includes modular architecture details, exploitation and persistence techniques, C2 retrieval mechanisms (public-hosted documents/profiles), extensive IoCs (hashes, IPs, signatures), and evidence of active abuse (Censys-identified infected hosts and Monero miners).