APT41 Targets Linux Cloud Servers With New Winnti Backdoor
ID: eccc1383-4b9c-52d9-8a92-dd367bf0edd5
STIX ID: report--eccc1383-4b9c-52d9-8a92-dd367bf0edd5
Feed Name: GBHackers
A newly discovered ELF backdoor attributed to APT41 (Winnti) targets multi-cloud workloads (AWS, GCP, Azure, Alibaba Cloud), using a novel SMTP-based C2 over port 25 with encoded payloads and tokenized EHLO handshakes to evade scanners; it harvests cloud credentials (metadata endpoints, config files, IAM/GCP/Azure/Alibaba tokens), encrypts stolen data with a hardcoded AES-256 key for exfiltration, and uses UDP broadcast beacons for lateral tasking. Researchers observed associated IOCs (C2 IP 43.99.48.196 and several typosquat domains) and trace this sample to a six-year evolution of Winnti Linux tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
