logo

APT41 Targets Linux Cloud Servers With New Winnti Backdoor

ID: eccc1383-4b9c-52d9-8a92-dd367bf0edd5

STIX ID: report--eccc1383-4b9c-52d9-8a92-dd367bf0edd5

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A newly discovered ELF backdoor attributed to APT41 (Winnti) targets multi-cloud workloads (AWS, GCP, Azure, Alibaba Cloud), using a novel SMTP-based C2 over port 25 with encoded payloads and tokenized EHLO handshakes to evade scanners; it harvests cloud credentials (metadata endpoints, config files, IAM/GCP/Azure/Alibaba tokens), encrypts stolen data with a hardcoded AES-256 key for exfiltration, and uses UDP broadcast beacons for lateral tasking. Researchers observed associated IOCs (C2 IP 43.99.48.196 and several typosquat domains) and trace this sample to a six-year evolution of Winnti Linux tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.