Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Wicked Panda, Brass Typhoon, BARIUM, G0096, TA415, Blackfly, Grayfly, LEAD, WICKED SPIDER, BRONZE ATLAS, BRONZE EXPORT, Red Kelpie, G0044, Earth Baku, Amoeba, HOODOO, Winnti, Double Dragon, TG-2633, Leopard Typhoon, Winnti Umbrella, APT41, tracked as, Taiwan, Suckfly, SPIRE CASTLE, so on

Description

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 2021)

Goals & Targeting

Targeted Sectors

Education
Energy
Financial services
Healthcare
Government
Media
Pharmaceutical
Retail
Telecommunications
Technology
Gaming
Transportation
Maritime
Aviation
Defense
Utilities
Hospitality
Manufacturing
Information technology
Mining
Critical infrastructure

Targeted Countries / Regions

CN
US
IN
TW
VN
GB

AI Analysis

· 1 week ago

Executive Summary

APT41, also known as Wicked Panda, is a Chinese state-sponsored threat group primarily involved in espionage activities with some financially motivated operations. Active since at least 2012, APT41 has targeted multiple sectors including technology, finance, and healthcare across numerous countries. The group is known for its sophisticated tactics, including the use of various malware families and tools to achieve its objectives.

Goals & Targeting

APT41's strategic goals include espionage and intelligence gathering, as well as financial gain. They target a broad range of sectors to collect sensitive information and disrupt business operations. Their victims typically include government agencies, critical infrastructure, and private sector entities with valuable data or intellectual property.

Enhanced Description

APT41 is a sophisticated Chinese state-sponsored cyber threat group that conducts both espionage and financially motivated operations. Known since at least 2012, APT41 has targeted industries such as technology, healthcare, financial services, telecommunications, education, media, pharmaceuticals, government, retail, and gaming across multiple countries. The group overlaps with known actors like BARIUM and Winnti Group, indicating potential affiliations or shared operational approaches.

Key Capabilities

  • Spear-phishing using malicious email attachments
  • Exploitation of software vulnerabilities
  • Malware deployment for persistence and data exfiltration
  • Credential theft and lateral movement within networks
  • Supply chain attacks to compromise third-party vendors
  • Use of custom tools like PlugX, Winnti, and DUSTTRAP

MITRE ATT&CK Tactics

Espionage
Initial Access
Execution
Persistence
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1037: Boot or Logon Initialization Scripts
T1087.002: Domain Account
T1056.001: Keylogging
T1014: Rootkit
T1133: External Remote Services
T1568.002: Domain Generation Algorithms
T1069: Permission Groups Discovery
T1003.002: Security Account Manager

Software / Tooling

DUSTTRAP
PlugX
China Chopper
ASPXSpy
Winnti for Linux
Cobalt Strike
njRAT
ShadowPad

Campaigns & Victims

APT41 has been involved in numerous campaigns targeting various industries globally. They often leverage supply chain attacks and custom malware to infiltrate networks undetected. Notable operations include compromises in the technology and financial sectors, where they deploy multiple stages of attack vectors to achieve their objectives.

IOC Patterns

  • Malicious emails with malicious attachments or links
  • Presence of known APT41 tools like PlugX or DUSTTRAP
  • Unusual network traffic signatures matching MITRE TTPs
  • Scheduled tasks created for persistence
  • Abnormal account activities indicating lateral movement

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to monitor for APT41's known tools.
  • Conduct regular audits of supply chain partners to mitigate potential attacks.
  • Enforce strict access controls and monitoring on sensitive data repositories.
  • Train employees to recognize phishing attempts and suspicious email patterns.

Suggested Tags

APT
espionage
financial-sector
state-sponsored

Confidence Assessment

High confidence in APT41's state-sponsored nature and operational techniques. Limited specifics on exact campaign details and some ambiguity in the group's exact structure remain.

ATT&CK Techniques

Collection
8 techniques
Command & Control
12 techniques
Credential Access
6 techniques
Defense impairment
7 techniques
Discovery
13 techniques
Execution
8 techniques
Initial Access
3 techniques
Lateral Movement
4 techniques
Persistence
8 techniques
Stealth
21 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 4 Domain 7 Filename 8 SHA-1 Hash 1

References

  1. Crowdstrike GTR2020 Mar 2020 — Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
  2. FireEye APT41 2019 — FireEye. (2019). Double DragonAPT41, a dual espionage andcyber crime operationAPT41. Retrieved September 23, 2019.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. Group IB APT 41 June 2021 — Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.
  5. www.group-ib.com — Cited by web research for: Suckfly
  6. attack.mitre.org — Cited by web research for: T1105
  7. www.huntress.com — Cited by web research for: phishing
  8. cloud.google.com — Cited by web research for: Hospitality

Intel Summary

106

Techniques

80

Tools

1

Campaigns

158

IOCs

0

Observed Data

15

Tactics

Tags

APT
Healthcare Targeting
Critical Infrastructure
espionage
financial-sector
state-sponsored

Details

MITRE ID
G0096
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
May 26, 2026
STIX ID
intrusion-set--18854f55-ac7c-4634-bd9a-352dd07613b7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.