• News/
  • https://www.darkreading.com/cyberattacks-data-breaches/china-linked-threat-group-japanese-orgs-servers

China-Linked Threat Group Targets Japanese Orgs' Servers

Dark Reading
·
Kristina Beek
·
Published Feb 18, 2025
·
Updated

NEWS BRIEF Winnti, a China-affiliated threat actor, has been linked to a new cyber campaign called RevivalStone, which has been observed targeting Japanese companies within the manufacturing, materials, and energy sectors. Winnti has been active since at least 2012, but only started targeting Asian manufacturing and materials organizations within the past few years. The group's activity, according to researchers at LAC, notably overlaps with a group known as Earth Freybug, a subset of APT41, a well-known cyber espionage group. In targeting organizations in the Asia-Pacific region, Winnti is exploiting vulnerabilities found in applications like IBM Lotus Domino to deploy malicious malware, including DEATHLOTUS, UNAPIMON, PRIVATELOG, CUNNINGPIGEON, WINDJAMMER, and SHADOWGAZE. LAC researchers have also observed Winnti exploiting an SQL injection vulnerability in an enterprise resource planning system to drop Web shells on an infected server. Once gaining access, the threat actor collects credentials, performs reconnaissance, and delivers the Winnti malware. This malware is an improved version, capable of expanding further to breach a managed service provider. According to a statement by the LAC researchers, "The new Winnti malware has been implemented with features such as obfuscation, updated encryption algorithms, and evasion by security products, and it is likely that this attacker group will continue to update the functions of the Winnti malware and use it in attacks."

Read full article

Affected Software

2 affected components
IBM Lotus Domino
IBM Lotus Domino
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyber campaign called RevivalStone, linked to the China-affiliated threat group Winnti, targeting Japanese organizations.

2

What security implications are discussed?

The article highlights the risks associated with cyber attacks on critical sectors like manufacturing, materials, and energy in Japan.

3

What specific organizations are targeted by the attackers?

Japanese companies in the manufacturing, materials, and energy sectors are the primary targets of the RevialStone campaign.

4

What products or software are affected by this cyber campaign?

IBM Lotus Domino is identified as affected software in this cyber campaign.

5

What threat actor is responsible for the RevivalStone campaign?

The threat actor responsible is Winnti, a group affiliated with China.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203