Winnti Group
MITRE ATT&CK: G0044 View on attack.mitre.org
Aliases: Blackfly, Winnti Group
- First seen
- 2010-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 11:58:28
Targeted industries: media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:cn country_code:us country_code:kr country_code:jp
Context
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.
Detection coverage
- 11 YARA rules
- 100 Sigma rules
Malware & tools used
- Rootkit (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Domains (attack-pattern)
- Process Discovery (attack-pattern)
- Code Signing (attack-pattern)
- PlugX (malware)
- PipeMon (malware)
- Winnti for Windows (malware)
Related threat objects
Reports & references
- Kaspersky — 37029 (report)
- Kaspersky — 70991 (report)
- MITRE ATT&CK — G0044 (report)
- Broadcom/Symantec — Suckfly Revealing Secret Life Your Code Signing Certificates (report)
- 401trg.github.io — Burning Umbrella (report)
- web.archive.org — Novetta Winntianalysis (report)
Attributed from
- Operation CuckooBees (campaign)