APT41__2019__Gaming-Industry.Asia.pdf
ID: e52cde5a-3ef3-4074-8f32-586659816dd7
STIX ID: report--e52cde5a-3ef3-4074-8f32-586659816dd7
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-03-12
Last Modified Date: 2019-03-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET reports multiple supply-chain compromises of game executables that embed a Winnti-family backdoor which hooks the PE entry point to decrypt and launch an in-memory DLL; the report details payload structure, RC4/RC5 encryption, C2 domains and IPs, available commands, second-stage Win64 components, IoCs (file hashes, domains, IPs), and victim distribution concentrated in Southeast Asia, noting that the attackers exclude Russian/Chinese locales.
