logo

APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor

ID: 11ff268b-5f95-50e4-bdd5-903e956ade87

STIX ID: report--11ff268b-5f95-50e4-bdd5-903e956ade87

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

A newly observed APT41-linked Linux backdoor targets cloud environments (AWS, Google Cloud, Microsoft Azure, Alibaba Cloud) to harvest credentials and metadata by querying cloud metadata services and local configuration files. The statically linked ELF sample used AES-256 to encrypt stolen data and exfiltrates via SMTP over port 25 while receiving commands hidden in SMTP responses; the campaign uses selective handshakes, typosquatted domains hosted on Alibaba Cloud (Singapore), and UDP broadcast for lateral movement, and was undetected by security platforms at discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.