BARIUM
WINNTI GROUP
APT41
WICKED PANDA
Threat IntelligenceAPTFebruary 25, 202615 min read

APT Barium: Threat Intelligence Profile

Chinese state-linked group conducting dual espionage and financial cybercrime operations, notorious for supply chain compromises and the ShadowPad backdoor.

Scroll

APT Barium / Winnti Umbrella (also known as Barium, Winnti Group, APT41, Wicked Panda) is a state-sponsored advanced persistent threat group attributed to China (MSS), active since 2012. The group primarily targets gaming, technology, healthcare, telecom sectors. It is tracked by MITRE ATT&CK as G0044.

Overview & Attribution

Chinese state-linked group conducting dual espionage and financial cybercrime operations, notorious for supply chain compromises and the ShadowPad backdoor.

Threat Assessment

APT Barium has been active since 2012, attributed to China (MSS). The group is known for targeting gaming, technology, healthcare, telecom using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

APT Barium employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on gaming, technology, healthcare, telecom sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

APT Barium is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1195.002 Supply Chain CompromiseSoftware supply chain attacks
ExecutionT1059.001 PowerShellScripted post-exploitation
PersistenceT1543.003 Windows ServiceService-based persistence
Defense EvasionT1027 Obfuscated FilesCode obfuscation
Lateral MovementT1021.002 SMB/Admin SharesNetwork lateral movement
C2T1573.001 Encrypted ChannelEncrypted C2 comms

Notable Campaigns

APT Barium has been linked to multiple significant campaigns targeting gaming, technology, healthcare, telecom organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against APT Barium

Mjolnir Security provides specialized capabilities to detect and respond to APT Barium operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for APT Barium TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of APT Barium campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 25, 2026