Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape

CUNNINGPIGEON

Tags
BackdoorMalware
Incidents
RevivalStone Campaign by Winnti
References
https://thehackernews.com/2025/02/winnti-apt41-targets-japanese-firms-in.html
Last edited
Feb 20, 2025 3:04 PM

CUNNINGPIGEON is a backdoor malware that leverages the Microsoft Graph API to establish covert communication channels with compromised systems. It is utilized by the China-linked advanced persistent threat (APT) group Winnti (also known as APT41) in their cyber espionage campaigns. CUNNINGPIGEON enables attackers to execute commands, manage files, and establish custom proxy functionalities by retrieving instructions embedded within Microsoft 365 mail messages.

Made with 💙 by Wiz

Last Updated: April 3, 2025