PULSE NAME
An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers
WHITE APT41 AlienVault 2018-05-04 Modified: 2019-11-25
516
IOCs
HIGH VOLUME
We assess with high confidence that the Winnti umbrella is associated with the Chinese state intelligence apparatus, with at least some elements located in the Xicheng District of Beijing. A number of Chinese state intelligence operations from 2009 to 2018 that were previously unconnected publicly are in fact linked to the Winnti umbrella. We assess with high confidence that multiple publicly reported threat actors operate with some shared goals and resources as part of the Chinese state intelligence apparatus. Report from Tom Hegel of 401TRG. Initial attack targets are commonly software and gaming organizations in United States, Japan, South Korea, and China. Later stage high profile targets tend to be politically motivated or high value technology organizations.
Indicators of Compromise (3 / 516 total)
All URL FileHash-SHA256 domain hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 9cf490fb6a40c821f03984bb11f4d7bdadbdc23f67b092a6c17e8a4a1b484ea9 2018-05-04
FileHash-SHA256 a1ad71f50b3ac7f60402677ff07f9c75fdd0259c87bdd4c7df3c8aeaf40af19e 2018-05-04
FileHash-SHA256 016250b7d62e49ba386404cc6db38cb65323d26cf80bc94e2810d5ab9e59fff2 2018-05-04