Overview
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
Campaigns — 2
APT41 DUST
ended2023-01 → 2024-06
Source: MITRE C0040
C0017
ended2021-05 → 2022-02
Source: MITRE C0017
T1078Valid AccountsStealth
T1082System Information DiscoveryDiscovery
T1195.002Compromise Software Supply ChainInitial Access
T1069Permission Groups DiscoveryDiscovery
T1595.003Wordlist ScanningReconnaissance
T1059.001PowerShellExecution
T1014RootkitStealth
T1087.002Domain AccountDiscovery
Malware & Tools — 32
ASPXSpyMalwareWindows
BITSAdminToolWindows
PlugXMalwareWindows
ImpacketToolLinux / macOS / Windows
gh0st RATMalwareWindows / macOS
netstatTool
PowerSploitToolWindows
ZxShellMalwareWindows
KEYPLUGMalwareLinux / Windows
Ping
T1555.003
Credentials from Web Browsers
Credential Access
T1036.005Match Legitimate Resource Name or LocationStealth
T1543.003Windows ServicePersistence
T1071.002File Transfer ProtocolsCommand and Control
T1018Remote System DiscoveryDiscovery
T1027.002Software PackingStealth
T1553.002Code SigningDefense Impairment
T1596.005Scan DatabasesReconnaissance
T1588.002ToolResource Development
T1098.007Additional Local or Domain GroupsPersistence
T1021.002SMB/Windows Admin SharesLateral Movement
T1037Boot or Logon Initialization ScriptsPersistence
T1136.001Local AccountPersistence
T1685.005Clear Windows Event LogsDefense Impairment
T1087.001Local AccountDiscovery
T1071.001Web ProtocolsCommand and Control
T1135Network Share DiscoveryDiscovery
T1599Network Boundary BridgingDefense Impairment
T1480.001Environmental KeyingStealth
T1484.001Group Policy ModificationDefense Impairment
T1595.002Vulnerability ScanningReconnaissance
T1005Data from Local SystemCollection
T1133External Remote ServicesPersistence
T1070.004File DeletionStealth
T1566.001Spearphishing AttachmentInitial Access
T1685Disable or Modify ToolsDefense Impairment
T1053.005Scheduled TaskExecution
T1547.001Registry Run Keys / Startup FolderPersistence
T1546.008Accessibility FeaturesPrivilege Escalation
T1110Brute ForceCredential Access
T1550.002Pass the HashLateral Movement
T1574.006Dynamic Linker HijackingStealth
T1059.003Windows Command ShellExecution
T1003.002Security Account ManagerCredential Access
T1568.002Domain Generation AlgorithmsCommand and Control
T1569.002Service ExecutionExecution
T1071.004DNSCommand and Control
T1046Network Service DiscoveryDiscovery
T1560.001Archive via UtilityCollection
T1102.001Dead Drop ResolverCommand and Control
Tool
LightSpyMalwareAndroid / Windows / iOS / macOS
China ChopperMalwareWindows
EmpireToolLinux / macOS / Windows
Cobalt StrikeMalwareLinux / macOS / Windows
BLACKCOFFEEMalwareWindows
Winnti for LinuxMalwareLinux
DerusbiMalwareWindows / Linux
ftpToolLinux / Windows / macOS