logo

APT41__2023__Symantec_Blackfly_Materials_Technology_02-28-2023.pdf

ID: cd46e686-d053-42cb-a46c-2043ef29f54f

STIX ID: report--cd46e686-d053-42cb-a46c-2043ef29f54f

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2023-03-01

Last Modified Date: 2023-03-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Blackfly (aka APT41/Winnti) is a Chinese-linked espionage group that recently targeted subsidiaries in the materials and composites sector to steal intellectual property; the Symantec report catalogs their 2022–2023 toolset (including a Winnkit rootkit/backdoor, credential-dumpers like Mimikatz, screenshotting and process-hollowing tools, proxy configurators and SQL clients), provides multiple SHA256 IOCs, and outlines mitigation/detection guidance.