China-Linked Threat Group Targets Japanese Orgs' Servers
ID: 266ba56d-f45a-5fd6-bc80-ff2f94ecd1a7
STIX ID: report--266ba56d-f45a-5fd6-bc80-ff2f94ecd1a7
Feed Name: Dark Reading
Date Published: 2025-02-18
Date Updated: 2026-05-05
Author: Kristina Beek, Associate Editor, Dark Reading
## Executive Summary Winnti (RevivalStone), a China‑affiliated APT linked to Earth Freybug/APT41, has been observed targeting Japanese manufacturing, materials, and energy companies by exploiting vulnerabilities in applications like IBM Lotus Domino and an ERP SQL injection to deploy web shells and multiple malware families (DEATHLOTUS, UNAPIMON, PRIVATELOG, CUNNINGPIGEON, WINDJAMMER, SHADOWGAZE). The actor collects credentials, conducts reconnaissance, and uses updated obfuscation, encryption, and evasion techniques to expand access — including breaches of managed service providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
