logo

APT41__2019__Gaming-Industry.Asia.pdf

ID: e52cde5a-3ef3-4074-8f32-586659816dd7

STIX ID: report--e52cde5a-3ef3-4074-8f32-586659816dd7

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-03-12

Last Modified Date: 2019-03-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET reports multiple supply-chain compromises of game executables that embed a Winnti-family backdoor which hooks the PE entry point to decrypt and launch an in-memory DLL; the report details payload structure, RC4/RC5 encryption, C2 domains and IPs, available commands, second-stage Win64 components, IoCs (file hashes, domains, IPs), and victim distribution concentrated in Southeast Asia, noting that the attackers exclude Russian/Chinese locales.