logo

Winnti Evolution - Going Open Source

ID: c6e4e30d-895b-4711-ac07-234b1eddc608

STIX ID: report--c6e4e30d-895b-4711-ac07-234b1eddc608

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2017-07-13

Last Modified Date: 2017-07-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ProtectWise describes a Winnti (APT17/Wicked Panda) campaign that uses spear-phishing résumé lures to deliver BeEF hooks and Meterpreter payloads (including JAR-delivered macOS components and MSI for Windows), leverages stolen code-signing certificates to sign malware, and operates C2 via lookalike domains and common ports; the post provides TTPs, target profiles (gaming, defense, ISPs), infrastructure indicators (domains and IPs), and attribution to China.