RevivalStone Campaign by Winnti (Campaign)
ID: 8db94f9a-7cc2-57b9-9e7c-25a19c459701
STIX ID: report--8db94f9a-7cc2-57b9-9e7c-25a19c459701
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-18
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
RevivalStone is a Winnti (APT41) cyber-espionage campaign observed in March 2024 targeting Japanese manufacturing, materials, and energy firms; attackers exploited an SQL injection in an ERP system to deploy web shells (China Chopper, Behinder), harvest credentials, move laterally via a compromised MSP, and deploy a suite of custom malware (DEATHLOTUS, CUNNINGPIGEON, PRIVATELOG, WINDJAMMER, SHADOWGAZE and an updated Winnti v5.0) for persistence, covert communication, and remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
