Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Blackfly
6
techniques
3
software
9,699
corpus matches
profile
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.
techniques
6 attributed · most-instrumented first
software
3 malware & tools attributed
PlugX
S0013
Winnti for Windows
S0141
PipeMon
S0501
read this carefully
9,699 corpus matches is not attribution
That count is indicators which exhibit techniques Winnti Group is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 9,699
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.