Winnti Evolution - Going Open Source
ID: c6e4e30d-895b-4711-ac07-234b1eddc608
STIX ID: report--c6e4e30d-895b-4711-ac07-234b1eddc608
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-07-13
Last Modified Date: 2017-07-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ProtectWise describes a Winnti (APT17/Wicked Panda) campaign that uses spear-phishing résumé lures to deliver BeEF hooks and Meterpreter payloads (including JAR-delivered macOS components and MSI for Windows), leverages stolen code-signing certificates to sign malware, and operates C2 via lookalike domains and common ports; the post provides TTPs, target profiles (gaming, defense, ISPs), infrastructure indicators (domains and IPs), and attribution to China.
