Patrocinio estatal: People's Republic of ChinaCategorías objetivo: Automotive, Business, Services, Cryptocurrency, Education, Energy, Financial, Healthcare, High-Tech, Intergovernmental, Media and Entertainment, Pharmaceuticals, Private sector, Retail, Telecommunications, Travel
Regiones atacadas: China · France · Hong Kong · India · Italy · Japan · Myanmar · Netherlands · Singapore · South Korea +6
También conocido como:AmoebaBARIUMBRONZE ATLASBRONZE EXPORTBlackflyBrass TyphoonDouble DragonEarth BakuG0044G0096GrayflyHOODOOLEADLeopard TyphoonRed KelpieSPIRE CASTLETA415TG-2633WICKED PANDAWICKED SPIDERWinnti
Sobre el grupo
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.
Técnicas (MITRE ATT&CK) 6
Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.
Preparación de recursos
Descubrimiento
Comando y control
defense-impairment
stealth
Vulnerabilidades explotadas
Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.
Referencias
El grupo Winnti Group usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.
Conocer el Pentest Autónomo con IA →