NEW: Group Profiler — instant APT intel lookup. Try it →

Winnti Group

G0044 China MITRE ATT&CK →

Also known as: Blackfly

Overview

Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.

Naming & attribution

Winnti Group is tracked under 2 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here. Activity attributed since at least 2010.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
BlackflyDiMaggio, J

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Molerats — 3 shared techniques (16% overlap)
  • Darkhotel South Korea — 4 shared techniques (15% overlap)
  • LuminousMoth China — 3 shared techniques (10% overlap)
  • Play — 3 shared techniques (10% overlap)
  • Winter Vivern Russia — 3 shared techniques (10% overlap)
  • TeamTNT — 5 shared techniques (9% overlap)

Targets

Automotive · Business · Cryptocurrency · Education · Energy · Finance · Healthcare · High-Tech · Intergovernmental · Media · Pharmaceuticals · Private sector · Retail · Services · Telecommunications · Travel

Regions

China · France · Hong Kong · India · Italy · Japan · Myanmar · Netherlands · Singapore · South Africa · South Korea · Switzerland · Thailand · Turkey · United Kingdom · United States

Capabilities

  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 6 techniques across 5 tactics

Resource Development

Stealth

Defense Impairment

Command and Control

Tools & malware (3)

PipeMon · Winnti for Windows · PlugX

Reporting (3)