AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Winnti Group
Aliases: Blackfly
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
1200km CTI repository · explicit report mentionOperation DragonRx — APT41 Full Attack Simulation
1200km CTI repository · explicit report mentionOperation DragonRx: Simulating an APT41 Attack End-to-End — From Log4Shell to DFIR and Malware Analysis
1200km CTI repository · explicit report mentionOperation DragonRx Simulating an APT41 Attack End to End From Log4Shell to DFIR and Malware
1200km Medium · authored report mention
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · explicit-nameModule 1 — Foundations: What CTI Is
Cyber Threat Intelligence (CTI) · explicit-nameModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · explicit-nameModule 6 — Active Directory and identity attack paths
Red Team & Offensive Security · explicit-nameModule 13 — Red-team infrastructure and operations
Red Team & Offensive Security · explicit-nameNetwork behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · explicit-nameShared responsibility, governance, and service ownership
Cloud Security · explicit-namePosture management, exposure, vulnerabilities, attack paths, and validation
Cloud Security · explicit-name