Alpha Cyber

Trillions-Dollar Heist: Mapping the Shadow Infrastructure of APT-41 (Winnti)

The digital landscape is currently haunted by one of the most sophisticated and relentless state-sponsored threats in history: APT-41 (also known as Winnti, BARIUM, or Double Dragon).

Alpha Cyber Research3 min readupdated 1 Apr 2026
Winnti APT Trillions Dollar Heist

Forensic Breakdown: APT-41’s Modified Execution Tactics

The digital landscape is currently haunted by one of the most sophisticated and relentless state-sponsored threats in history: APT-41 (also known as Winnti, BARIUM, or Double Dragon). Unlike typical threat actors who choose between espionage or profit, APT-41 is a “Dual Operation” powerhouse, executing government-mandated intelligence thefts alongside financially motivated heists.

This group is credited with the theft of an estimated trillion dollars in intellectual property, targeting everything from pharmaceutical formulas to aerospace blueprints. At our firm, we provide more than just detection; we offer Infrastructure Mapping a proactive service that identifies the invisible architecture used by these predators to maintain persistence for years.

Forensic Intelligence: The Capa & PE Breakdown

During our latest deep-dive into the “Running Rat” and associated Winnti components, our advanced forensic telemetry identified a series of high-level malicious behaviors that confirm the group’s signature tradecraft.

1. Environmental & Evasion Tactics

Capa Winnti APT-41 Running Rat

APT-41 employs a “Look Before You Leap” strategy. Analysis of recent samples reveals deep Anti-Behavioral Analysis techniques:

  • Virtual Machine Detection [B0009]: The malware specifically targets Xen-based virtualization strings. If it detects a sandbox or a researcher’s environment, it remains dormant, effectively “ghosting” automated security tools.

  • Obfuscated Stackstrings [B0032.017]: Instead of storing visible commands, the malware constructs strings in memory at runtime. This bypasses static scanners that rely on identifying “known-bad” strings within a file.

2. Advanced Execution & Persistence

The “Running Rat” variant is a masterclass in stealthy execution:

  • Runtime Function Linking: By linking Windows functions at runtime, the malware maintains a clean “Import Table,” making it appear like a benign utility until it is deep within the system memory.

  • Threaded Decoupling: The use of CreateThread allows the malicious logic to run independently of the main process, making behavioral monitoring significantly more complex for standard EDR solutions.

  • PE Section Enumeration: Our mapping shows the malware scanning its own internal sections to locate and decrypt second-stage payloads hidden within compressed resources.

Supply Chain & Infrastructure Mapping

VirusTotal Winnti APT Running Rat Graph

The true danger of APT-41 lies in their Supply Chain Compromise (T1195). By infiltrating software development environments, they inject malicious code into legitimate updates, essentially using a company’s own trust against them.

Our mapping services go beyond the endpoint, identifying the C2 (Command & Control) infrastructure used to manage these global infections. Below is the intelligence gathered from the most recent campaign involving Win32/HackedApp.Winnti and Win64/Winnti.BN components.

Indicators of Compromise (IoCs) to Block

To protect your environment from this trillion-dollar threat, we have compiled a de-duplicated and verified list of indicators. Immediate blocking and retrospective auditing of these hashes and domains are highly recommended.

Primary Malware & Payloads

Component NameHash (SHA-1)Details / C2 URLRecommended Action
HackedApp.Winnti.A474b1c81de1eafe93602c297d701418658cf6febCompiled: Jul 2018Block & Isolate
HackedApp.Winnti.Ba085e0d484703f5fd45b161d446789c6096362abRC4 Key: 207792894a04Block & Isolate
Win32/Winnti.AGa260dcf193e747cee49ae83568eea6c04bf93cb3bugcheck.xigncodeservice[.]comBlock & Audit
Win32/Winnti.AG8272c1f41f7c223316c0d78bd3bd5744e25c2e9fnw.infestexe[.]comBlock & Audit
Win64/Winnti.BNbb4ab0d8d05a3404f1f53f152ebd79f4ba4d4d81checkin.travelsanignacio[.]comBlock & Isolate
PoisonPlug1835c7751436cc199c55b42f34566d25fe6104caMandiant Table 21Block & Isolate
HighNoon.bin1036a7088b060250bb66b6de91f0c6ac462dc24cPersistence via DLLBlock & Isolate

High-Risk Network Indicators

The following domains are currently associated with APT-41’s global staging and C2 infrastructure:

  • bugcheck.xigncodeservice[.]com

  • gxxservice[.]com

  • infestexe[.]com

  • kasparsky[.]net (Typosquatting)

  • micros0ff[.]com / micros0tf[.]com

  • symanteclabs[.]com

  • api.goallbandungtravel[.]com

Conclusion: Why Infrastructure Mapping Matters

APT-41 does not play by the rules. They use stolen digital certificates to sign their malware and compromised government websites to host their payloads. Detecting a single hash is not enough; you must understand the map of their operations to stay ahead.

Our infrastructure mapping service provides:

  1. C2 Correlation: We track the movement of backdoors across global hop-points.

  2. Technique Fingerprinting: We identify unique encryption keys (like the RC4 keys listed above) to find hidden threats.

  3. Proactive Takedowns: We work to neutralize staging servers before they target your intellectual property.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]