Winnti (Windows)

Aliases: BleDoor, JUMPALL, Pasteboy, RbDoor

First seen
2010-01-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 12:38:29

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications media-and-entertainment government-and-public-sector energy-and-utilities

Targeted regions: country_code:cn country_code:hk country_code:tw country_code:sg country_code:ru country_code:vn country_code:th

Context

Winnti is a well-known malware family used by a Chinese state-sponsored threat group. It is primarily used for cyber-espionage and long-term intrusions in targeted industries, often implementing backdoor and RAT capabilities.

Related threat objects

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Kaspersky — 70991 (report)
  • secureworks.com — Bronze Atlas (report)
  • MITRE ATT&CK — G0096 (report)
  • CrowdStrike — Report2021Gtr (report)
  • i.blackhat.com — Us 20 Chen Operation Chimera Apt Operation Targets Semiconductor Vendors (report)
  • wired.com — Chinese Hackers Taiwan Semiconductor Industry Skeleton Key (report)
  • hello.global.ntt — The Operations Of Winnti Group (report)
  • Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
  • recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
  • i.blackhat.com — As 22 Leonsilvia Nextgenplugxshadowpad (report)
  • recordedfuture.com — China Linked Tag 28 Targets Indias The Times Group (report)
  • ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
  • blog.bushidotoken.net — Gamer Cheater Hacker Spy (report)
  • Kaspersky — 99204 (report)
  • blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
  • macnica.net — Mpressioncss 2018 1H Report Mnc Rev3 Nopw (report)
  • Mandiant — Rpt Apt41 (report)
  • youtube.com — Watch (report)
  • Broadcom/Symantec — Apt41 Indictments China Espionage (report)
  • malwarebytes.com — Winnti Apt Group Docks In Sri Lanka For New Campaign Final (report)
  • Mandiant — Pdfproxy (report)

External references