Winnti Group

APT / StateG0044 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)6
SourceMITRE ATT&CK
State sponsor: People's Republic of ChinaTarget categories: Automotive, Business, Services, Cryptocurrency, Education, Energy, Financial, Healthcare, High-Tech, Intergovernmental, Media and Entertainment, Pharmaceuticals, Private sector, Retail, Telecommunications, Travel
Targeted regions: China · France · Hong Kong · India · Italy · Japan · Myanmar · Netherlands · Singapore · South Korea +6
Also known as:AmoebaBARIUMBRONZE ATLASBRONZE EXPORTBlackflyBrass TyphoonDouble DragonEarth BakuG0044G0096GrayflyHOODOOLEADLeopard TyphoonRed KelpieSPIRE CASTLETA415TG-2633WICKED PANDAWICKED SPIDERWinnti

About the group

Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.

Techniques (MITRE ATT&CK) 6

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Resource development
Command and control
defense-impairment
stealth

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Winnti Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →