Uptime Hamster: 10d 12h 18mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza SparklingGoblin

SparklingGoblin

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: CROSSWALK, SideWalk, Winnti, lo que sugiere una amplia red de actividades maliciosas
Ver en IntelTracker → APTTrail →
SparklingGoblin is a cyber-espionage threat actor first identified with specific campaigns in May 2020, operating with high confidence from China. This group's primary motivation is intelligence gathering, focusing on intellectual property theft and sensitive data exfiltration. While closely associated with and considered by some to be an alias of the broader Winnti Group, also known as APT41, Barium, Wicked Panda, and Grayfly, SparklingGoblin exhibits distinct operational patterns that have led researchers to track it as a separate entity. A defining characteristic of SparklingGoblin is its exclusive use of the SideWalk backdoor.

Aliases del actor

CROSSWALKSideWalkWinntilo que sugiere una amplia red de actividades maliciosas

Actores similares

lunalockransomware · 2redalertransomware · 2redransomwareransomware · 2Scattered Spideractor · 2redactactor · 2Scattered Lapsus$ Huntersthreat-actor · 1redcontroleactor · 1apt-redbaldknightactor · 1apt-redfoxtrotactor · 1apt-redjuliettactor · 1
Motivacion