APT41 targets Linux cloud servers with new Winnti backdoor built to steal credentials
VPN Central [Unofficial]
April 16, 2026
APT41 is expanding its Linux toolset again, this time with a backdoor built for cloud workloads. Recent reporting says the group deployed a new Winnti-family ELF implant that targets Linux servers running in AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud environments, with the goal of stealing cloud credentials and maintaining quiet access over time. […]
The post APT41 targets Linux cloud servers with new Winnti backdoor built to steal credentials appeared first on VPN Central.
Discussion in the ATmosphere