Winnti — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
April 13, 2026
Last Seen
June 17, 2026

Related Threat Clusters

  • APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor

    APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…

    6 articles · Updated April 13, 2026
  • FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth

    ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…

    12 articles · Updated June 16, 2026
  • Bitdefender Achieves 100% Telemetry in EDR Test

    Bitdefender GravityZone Business Security Enterprise achieved 100% relevant telemetry in AV-Comparatives’ inaugural EDR Detection Validation Certification Test published in May 2026. This certification tested the…

    2 articles · Updated May 15, 2026

Recent Intelligence Reports

  • Advanced Kernel — Rescana · June 17, 2026
  • Bitdefender GravityZone: 100% Telemetry in AV — Bitdefender · May 15, 2026
  • Bitdefender GravityZone: 100% Telemetry in AV — Bitdefender · May 14, 2026
  • China — Csoonline · April 14, 2026
  • APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor — Cybersecuritynews · April 14, 2026
  • APT41 Targets Linux Cloud Servers With New Winnti Backdoor — Gbhackers · April 14, 2026
  • Apt41 Winnti Elf Cloud Credential Harvester Alibaba Typosquat — intel.breakglass.tech · April 13, 2026
  • APT41 Delivers 'Zero-Detection' Backdoor to Harvest Cloud Credentials — Darkreading · April 13, 2026

CVSS v3.1 Breakdown