logo

China-Linked Threat Group Targets Japanese Orgs' Servers

ID: 266ba56d-f45a-5fd6-bc80-ff2f94ecd1a7

STIX ID: report--266ba56d-f45a-5fd6-bc80-ff2f94ecd1a7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-02-18

Date Updated: 2026-05-05

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

## Executive Summary Winnti (RevivalStone), a China‑affiliated APT linked to Earth Freybug/APT41, has been observed targeting Japanese manufacturing, materials, and energy companies by exploiting vulnerabilities in applications like IBM Lotus Domino and an ERP SQL injection to deploy web shells and multiple malware families (DEATHLOTUS, UNAPIMON, PRIVATELOG, CUNNINGPIGEON, WINDJAMMER, SHADOWGAZE). The actor collects credentials, conducts reconnaissance, and uses updated obfuscation, encryption, and evasion techniques to expand access — including breaches of managed service providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.