Winnti hacking crew targets pharmaceutical and telecommunications companies
Kaspersky security experts have collected evidence that the hacking group called Winnti APT is moving beyond gaming businesses and targeting large pharmaceutical and telecommunications companies.
Those with a good memory will remember the Winnti group, a Chinese APT discovered by Kaspersky Lab in 2013 that targeted the gaming industry.
According to experts, the Winnti gang has been active since 2009, targeting more than 30 gambling businesses and hitting various popular online games. Recently, Kaspersky experts discovered that ATP has now changed its focus and now has its sights set beyond the entertainment industry.
In April, Novetta experts published a report on the Winnti malware, which was detected in the actions of a Chinese APT called Axiom group. The Axiom group carries out cyber-espionage campaigns in various industries.
One of the drivers included in the latest variant of Winniti malware detected by researchers (Winniti 3.0), the Winnti network rootkit, was signed with a stolen certificate from a division of a Japanese conglomerate. Kaspersky experts noted that this conglomerate includes, among other things, the development and production of pharmaceuticals and medical equipment.
"Although this division is engaged in the manufacture of microelectronics, the areas of other businesses of the same group include the development and production of medicines as well as medical equipment," Dmitry Tarakanov, a security researcher at Kaspersky Lab, said in a blog post.
Researchers have not yet released any information regarding the involvement of Winnti operators, the only certainty at this time is that the group is taking a step beyond the online gambling industry, and is running cyber-espionage campaigns on other businesses and different industries, including big pharmaceuticals and telecommunications.


