Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:08:36 UTC Home > List all groups > List all tools > List all groups using tool WINGCRACK Tool: WINGCRACK Names WINGCRACK Category Malware Type Credential stealer Description (Mandiant) WINGCRACK is a utility that can decode and display the content of files containing encoded keylog data from WINGHOOK. The malware author appears to refer to these encoded files as “schwing” files. Information Last change to this tool card: 03 April 2022 Download this tool card in JSON format All groups using tool WINGCRACK Changed Name Country Observed APT groups   UNC2891 [Unknown] 2020   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a4a9d8f9-54ff-4d1d-8ddb-2271469b1258 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a4a9d8f9-54ff-4d1d-8ddb-2271469b1258 Page 1 of 1