Winnti Group

MITRE
Type:
Unknown
Country:
Unknown
First seen:
Unknown
Details:

[Winnti Group](https://attack.mitre.org/groups/G0044) is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting.(Citation: Kaspersky Winnti April 2013)(Citation: Kaspersky Winnti June 2015)(Citation: Novetta Winnti April 2015) Some reporting suggests a number of other groups, including [Axiom](https://attack.mitre.org/groups/G0001), [APT17](https://attack.mitre.org/groups/G0025), and [Ke3chang](https://attack.mitre.org/groups/G0004), are closely linked to [Winnti Group](https://attack.mitre.org/groups/G0044).(Citation: 401 TRG Winnti Umbrella May 2018)

MITRE ATT&CK: View on MITRE
Techniques Used (6)
ID ATT&CK Tactics
T1014 Rootkit -
T1057 Process Discovery -
T1083 File and Directory Discovery -
T1105 Ingress Tool Transfer -
T1553.002 Code Signing -
T1583.001 Domains -
Aliases (105)
Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly Blackfly
Metadata
ID: 904
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00