Full Report
The China-linked APT group Winnti (APT41) has been linked to a new cyber espionage campaign, RevivalStone, targeting Japanese manufacturing, materials, and energy companies in March 2024. The attack, detailed by LAC, exploited an SQL injection vulnerability in an unspecified E...
Analysis Summary
# Threat Actor: Winnti (APT41)
## Attribution & Identity
China-linked APT group.
**Known Aliases/Associated Groups:** APT41
## Activity Summary
Linked to a new cyber espionage campaign named **RevivalStone**, observed targeting Japanese companies in **March 2024**. The attack leveraged an SQL injection vulnerability in an unspecified ERP system for initial access, deployment of web shells, reconnaissance, and credential harvesting. The attackers subsequently moved laterally and compromised a Managed Service Provider (MSP), which was then used to propagate malware to three additional victim organizations.
## Tactics, Techniques & Procedures
- Initial Access via **SQL Injection vulnerability** in an unspecified ERP system.
- **Webshell deployment** (China Chopper, Behinder).
- **Credential theft**.
- **Network lateral movement** (including breach of an MSP).
- **Persistence, covert communication, and remote control** using custom toolset.
- Deployment of an updated version of the main implant (**Winnti v5.0**) with improved obfuscation, encryption, and security evasion.
- Leveraging infrastructure controllers like **TreadStone** (linked to the I-Soon leak).
## Targeting
- **Sectors:** Manufacturing, Materials, and Energy companies.
- **Geography:** Japan (Asia-Pacific region).
- **Victims:** Japanese private sector firms and a compromised Managed Service Provider (MSP) used as a pivot point.
## Tools & Infrastructure
- **Malware Families/Backdoors:**
- DEATHLOTUS (CGI backdoor)
- CUNNINGPIGEON (Graph API backdoor)
- PRIVATELOG (malware loader)
- WINDJAMMER (rootkit)
- SHADOWGAZE (passive IIS backdoor)
- Winnti RAT (v5.0 observed)
- **Web Shells:** China Chopper, Behinder
- **Infrastructure Controllers:** TreadStone, StoneV5 (potentially related to Winnti v5.0)
- **Targeted Technologies:** Microsoft IIS, Microsoft Graph API, ERP Systems.
## Implications
RevivalStone demonstrates Winnti's continued focus on strategic cyber espionage against critical industries in the Asia-Pacific region, aligning with China's intelligence objectives. The group showcases high adaptability by exploiting zero-day-like vulnerabilities (1-day SQLi) and leveraging supply chain vectors via MSPs to amplify impact and maintain stealth.
## Mitigations
- Focus on rapidly patching known vulnerabilities, especially those affecting public-facing applications like ERP systems and web servers (IIS).
- Implement strict network segmentation, particularly isolating MSP environments from core enterprise networks.
- Enhanced monitoring for web shell activity and lateral movement techniques, including monitoring for known tools like China Chopper and Behinder.
- Implement robust endpoint detection and response (EDR) capable of detecting custom backdoors like DEATHLOTUS and rootkits like WINDJAMMER.
- Monitor for indicators related to the Winnti toolset and its infrastructure usage.