BARIUM
- First seen
- 2015-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Actor type
- nation-state
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 12:30:55
Targeted industries: media-and-entertainment technology-and-telecommunications
Context
Microsoft Threat Intelligence associates Winnti with multiple activity groups—collections of malware, supporting infrastructure, online personas, victimology, and other attack artifacts that the Microsoft intelligent security graph uses to categorize and attribute threat activity. Microsoft labels activity groups using code names derived from elements in the periodic table. In the case of this malware, the activity groups strongly associated with Winnti are BARIUM and LEAD. But even though they share the use of Winnti, the BARIUM and LEAD activity groups are involved in very different intrusion scenarios. BARIUM begins its attacks by cultivating relationships with potential victims—particularly those working in Business Development or Human Resources—on various social media platforms. Once BARIUM has established rapport, they spear-phish the victim using a variety of unsophisticated malware installation vectors, including malicious shortcut (.lnk) files with hidden payloads, compiled HTML help (.chm) files, or Microsoft Office documents containing macros or exploits. Initial intrusion stages feature the Win32/Barlaiy implant—notable for its use of social network profiles, collaborative document editing sites, and blogs for C&C. Later stages of the intrusions rely upon Winnti for persistent access. The majority of victims recorded to date have been in electronic gaming, multimedia, and Internet content industries, although occasional intrusions against technology companies have occurred.
Related threat objects
- APT41 (threat-actor)
Reports & references
- Microsoft — Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp (report)