APT41 is once again pushing its Linux capabilities forward, this time by quietly turning cloud servers into powerful credential theft platforms. The group’s latest Winnti-family backdoor is a zero‑detection ELF implant designed specifically for Linux workloads running on AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud, with a clear focus on stealing cloud credentials at […]
The post APT41 Turns Linux Cloud Servers Into Credential Theft Targets With New Winnti Backdoor appeared first on Cyber Security News.
Read the original article: