APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor
ID: 11ff268b-5f95-50e4-bdd5-903e956ade87
STIX ID: report--11ff268b-5f95-50e4-bdd5-903e956ade87
Feed Name: Cyber Press
A newly observed APT41-linked Linux backdoor targets cloud environments (AWS, Google Cloud, Microsoft Azure, Alibaba Cloud) to harvest credentials and metadata by querying cloud metadata services and local configuration files. The statically linked ELF sample used AES-256 to encrypt stolen data and exfiltrates via SMTP over port 25 while receiving commands hidden in SMTP responses; the campaign uses selective handshakes, typosquatted domains hosted on Alibaba Cloud (Singapore), and UDP broadcast for lateral movement, and was undetected by security platforms at discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
