logo

China-linked APT group Winnti targets Japanese organizations since March 2024

ID: 9c2a6704-59d2-5536-bd62-85603f4ce9ec

STIX ID: report--9c2a6704-59d2-5536-bd62-85603f4ce9ec

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-02-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers from LAC attributed a March 2024 campaign called RevivalStone to the China-linked Winnti APT, which exploited an ERP SQL injection to deploy WebShells, performed reconnaissance and lateral movement via a compromised maintenance provider account, and deployed an enhanced Winnti toolset (Loader/PRIVATELOG, RAT, Rootkit) using DLL hijacking, SessionEnv persistence, and obfuscation to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.