Security researchers at Positive Technologies have uncovered a series of attacks carried out by a Chinese APT hacking group, targeting organizations in Russia and Hong Kong. Experts attribute the attacks to the China -linked Winnti APT group (also known as APT41), and said the attackers used an old , unidentified backdoor in their attacks
The Winnti group was first detected by Kaspersky in 2013, but according to researchers, it has been active since 2007. Experts believe that Winnti is made up of several other APT groups, including Winnti, Gref, PlayfullDragon, APT17, DeputyDog, Axiom, BARIUM, LEAD, PassCV, Wicked Panda, Group 72, Blackfly, and ShadowPad. The APT group targets organizations in various industries, including aviation, gaming, pharmaceuticals, technology, telecommunications, and software.

The recent attacks discovered by Positive Technologies were first spotted on May 12, 2020, when experts spotted several samples of the new malware that had initially been incorrectly attributed to the Higaisa hackers. While investigating the attack, experts discovered a number of new malware samples used by the attackers, including various droppers, loaders, and injectors. The attackers also used the Crosswalk, ShadowPad, and PlugX backdoors, but security researchers also observed a sample of an unspecified backdoor they named “FunnySwitch.”
In the first attack, hackers used LNK shortcuts to extract and execute the malware payload , while in the second attack detected on May 30, they used a malicious file (CV_Colliers.rar) containing the shortcuts to two decoy PDF documents with a CV and IELTS certificate
The Winnti group focuses on the computer gaming industry, having previously targeted game developers and recently hit Russian companies in the same industry. The targets of recent attacks include Battlestate Games, a Unity3D game developer from St. Petersburg.

In June, researchers detected an active HttpFileServer on one of the active C2 servers. The HFS contained an email icon, a screenshot of a game with Russian text, a screenshot of a game developer's website, and a screenshot of information about the CVE-2020-0796 vulnerability from Microsoft. The files were used two months later, on August 20, 2020, in attacks that also exploited a standalone loader for the Cobalt Strike Beacon PL shellcode.
The discovery led experts to believe they had identified traces of a preparation and, subsequently, successful implementation of an attack against Battlestate Games.
Winnti continues to target game developers and publishers in Russia and other countries. Small studios tend to neglect information security, which makes them vulnerable to attacks. Attacks on software developers are particularly dangerous as they expose end users, as has already happened in the well-known cases of CCleaner and ASUS. By ensuring timely detection and investigation of breaches, companies can avoid falling victim to such a scenario.
