logo

Winnti's new UNAPIMON tool hides malware from security software

ID: a4ceb300-1617-5ab5-8f93-24e21e3c3312

STIX ID: report--a4ceb300-1617-5ab5-8f93-24e21e3c3312

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-04-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trend Micro attributes an ongoing cyberespionage operation called 'Earth Freybug' to Winnti/APT41, describing a novel C++ DLL malware (UNAPIMON) that uses Microsoft Detours to intercept CreateProcessW, start child processes suspended, copy and load DLLs from %User Temp%, detect and remove security-product hooks, then resume execution—allowing malicious payloads to execute undetected after VMTools process injection and DLL sideloading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.