Winnti Group
Also known as: Blackfly
Overview
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.
Naming & attribution
Winnti Group is tracked under 2 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here. Activity attributed since at least 2010.
| Name | First reported by |
|---|---|
| Blackfly | DiMaggio, J |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Molerats — 3 shared techniques (16% overlap)
- Darkhotel South Korea — 4 shared techniques (15% overlap)
- LuminousMoth China — 3 shared techniques (10% overlap)
- Play — 3 shared techniques (10% overlap)
- Winter Vivern Russia — 3 shared techniques (10% overlap)
- TeamTNT — 5 shared techniques (9% overlap)
Targets
Automotive · Business · Cryptocurrency · Education · Energy · Finance · Healthcare · High-Tech · Intergovernmental · Media · Pharmaceuticals · Private sector · Retail · Services · Telecommunications · Travel
Regions
China · France · Hong Kong · India · Italy · Japan · Myanmar · Netherlands · Singapore · South Africa · South Korea · Switzerland · Thailand · Turkey · United Kingdom · United States
Capabilities
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 6 techniques across 5 tactics
Resource Development
-
T1583.001Domains
Stealth
-
T1014Rootkit
Defense Impairment
-
T1553.002Code Signing
Discovery
-
T1057Process Discovery -
T1083File and Directory Discovery
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (3)
PipeMon · Winnti for Windows · PlugX