APT41__2023__Symantec_Blackfly_Materials_Technology_02-28-2023.pdf
ID: cd46e686-d053-42cb-a46c-2043ef29f54f
STIX ID: report--cd46e686-d053-42cb-a46c-2043ef29f54f
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2023-03-01
Last Modified Date: 2023-03-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Blackfly (aka APT41/Winnti) is a Chinese-linked espionage group that recently targeted subsidiaries in the materials and composites sector to steal intellectual property; the Symantec report catalogs their 2022–2023 toolset (including a Winnkit rootkit/backdoor, credential-dumpers like Mimikatz, screenshotting and process-hollowing tools, proxy configurators and SQL clients), provides multiple SHA256 IOCs, and outlines mitigation/detection guidance.
