APT41, a China-linked threat group, has deployed a new Linux ELF backdoor from the Winnti malware family to compromise cloud workloads and steal credentials from AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud environments. Researchers said the implant was built for stealth rather than disruption, harvesting metadata, temporary tokens, and local credential files while evading common detection methods; at the time of analysis, it reportedly had zero detections on VirusTotal. The malware abuses cloud metadata services, including the AWS instance metadata endpoint 169.254.169.254, creating a path to broader cloud access when attached permissions are overly permissive.
The campaign uses unusual tradecraft to blend into normal operations, including SMTP-based command and control over port 25, a selective handshake mechanism that limits exposure during scanning, and UDP broadcast beacons on port 6006 that may support lateral movement. Investigators also linked the activity to typosquatted domains themed around Alibaba Cloud and Qianxin, with infrastructure reportedly registered through NameSilo and hosted in part on Alibaba Cloud in Singapore. Defenders were urged to monitor outbound SMTP from non-mail systems, watch for abnormal UDP broadcasts, audit metadata API access, enforce protections such as AWS IMDSv2, and strengthen cloud logging through services such as CloudTrail and Google Cloud Audit Logs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Breakglass Intelligence publicly reported that the backdoor had zero detections on VirusTotal at the time of analysis and described its stealth features, cloud credential theft behavior, and attribution links to earlier Winnti-related Linux implants. The firm also recommended detections such as monitoring outbound SMTP from non-mail workloads, auditing metadata API access, and enabling stronger cloud logging and identity controls.
APT41 used a Linux ELF/Winnti-family backdoor against cloud workloads to harvest metadata and temporary credentials from AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud environments. The malware used SMTP port 25 as a covert command-and-control channel and supported lateral movement via UDP broadcast traffic on port 6006.
Breakglass Intelligence released infrastructure indicators and hunting content for the APT41/Winnti Linux backdoor campaign, including YARA and Suricata detections tied to typosquatted domains and Alibaba Cloud-hosted command-and-control infrastructure. The report also documented the malware's cloud credential harvesting and covert SMTP-based C2 behavior.
Infrastructure linked to the campaign was registered through NameSilo over a 24-hour period on January 20-21, 2026, using WHOIS privacy. The domains mimicked Alibaba Cloud services and the Chinese cybersecurity brand Qianxin, consistent with prior APT41 tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedarkreading.com
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.