PULSE NAME
An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers
WHITE APT41 AlienVault 2018-05-04 Modified: 2019-11-25
516
IOCs
HIGH VOLUME
We assess with high confidence that the Winnti umbrella is associated with the Chinese state intelligence apparatus, with at least some elements located in the Xicheng District of Beijing. A number of Chinese state intelligence operations from 2009 to 2018 that were previously unconnected publicly are in fact linked to the Winnti umbrella. We assess with high confidence that multiple publicly reported threat actors operate with some shared goals and resources as part of the Chinese state intelligence apparatus. Report from Tom Hegel of 401TRG. Initial attack targets are commonly software and gaming organizations in United States, Japan, South Korea, and China. Later stage high profile targets tend to be politically motivated or high value technology organizations.
Indicators of Compromise (22 / 516 total)
All URL FileHash-SHA256 domain hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1217cbb57fb26bd52d976f34571bd6c6514265e9 2018-05-04
FileHash-SHA1 12eb8a9f1a7cd1cc10e57847dd5476c6062b9e58 2018-05-04
FileHash-SHA1 1cc87c7c900d584400c5c82073672888fefb145e 2018-05-04
FileHash-SHA1 23d57a493a5bfe1801b9d6e0894555242661a27b 2018-05-04
FileHash-SHA1 263babc25c177e0e6bd87c687bad8316240f971e 2018-05-04
FileHash-SHA1 3f3da327ca330396f1ab0a543be284f85d9d414a 2018-05-04
FileHash-SHA1 512509787e4da7aaf71b89d25698a9e9d43501fd 2018-05-04
FileHash-SHA1 58e1a9c1dae311fabdfa065955216a46eecb5816 2018-05-04
FileHash-SHA1 5a1c6ae9e2633df29c01a2668538e0203de375b2 2018-05-04
FileHash-SHA1 5e0fa58bf1c4c1b63144052063dc2bb9129aa1f3 2018-05-04
FileHash-SHA1 8df0b63fbdd9616d581bdb101929eb17f80f9e99 2018-05-04
FileHash-SHA1 8e11362a487a744fd21682cd86ad053e8bd5b9ce 2018-05-04
FileHash-SHA1 8e400380e376b9fb03612967940bb8e07175ab6a 2018-05-04
FileHash-SHA1 92a1c7e1fd5afccd957e7fcbcdd2431eb9bf3d50 2018-05-04
FileHash-SHA1 93caf237baa37cd42dfc4653ffc1792fcbad4642 2018-05-04
FileHash-SHA1 a22d97e4ede82ae8375522aca59db575d08c5c35 2018-05-04
FileHash-SHA1 aff17a2e1969e4bf81dbaa3591778887546570cb 2018-05-04
FileHash-SHA1 bd3abf19f065d102503e9186c152e529d3e33143 2018-05-04
FileHash-SHA1 c3e55bd6fe0205fe7dc1ad53ed03db269ba5da71 2018-05-04
FileHash-SHA1 ca2854658dff72da77bf82c1fe5899d09f9f559d 2018-05-04
FileHash-SHA1 ddf115821717dabb5e69c753d27460242204031e 2018-05-04
FileHash-SHA1 df7826303b98004afd1102f597f6c7b067086a00 2018-05-04