Winnti Group

MITRE ATT&CK: G0044 View on attack.mitre.org

Aliases: Blackfly, Winnti Group

First seen
2010-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-19 10:45:03
Profile updated
2026-07-07 11:58:28

Targeted industries: media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:cn country_code:us country_code:kr country_code:jp

Context

Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.

Detection coverage

  • 11 YARA rules
  • 100 Sigma rules

Malware & tools used

  • Rootkit (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Domains (attack-pattern)
  • Process Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • PlugX (malware)
  • PipeMon (malware)
  • Winnti for Windows (malware)

Related threat objects

Reports & references

  • Kaspersky — 37029 (report)
  • Kaspersky — 70991 (report)
  • MITRE ATT&CK — G0044 (report)
  • Broadcom/Symantec — Suckfly Revealing Secret Life Your Code Signing Certificates (report)
  • 401trg.github.io — Burning Umbrella (report)
  • web.archive.org — Novetta Winntianalysis (report)

Attributed from

  • Operation CuckooBees (campaign)

External references