APT41
MITRE ATT&CK: G0096 View on attack.mitre.org
Aliases: Wicked Panda, Brass Typhoon, BARIUM, TA415, Blackfly, Grayfly, LEAD, WICKED SPIDER, WICKED PANDA, BRONZE ATLAS, BRONZE EXPORT, Red Kelpie, Earth Baku, Amoeba, HOODOO, Winnti, Double Dragon, TG-2633, Leopard Typhoon, APT41, TG-3279, Mana, KAOS, Red Diablo, Winnti Group
- First seen
- 2012-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state, criminal
- Related IoCs
- 7 (4 malicious)
- Last IoC activity
- 2026-09-03 02:19:48
- Profile updated
- 2026-07-07 12:32:29
Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Targeted regions: country_code:us country_code:de country_code:jp country_code:au country_code:ca country_code:uk country_code:it country_code:fr country_code:ru country_code:in country_code:kr country_code:br country_code:mx country_code:id
Context
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to APT41 (G0096). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | PCG_124th_Anniversary_Event_Documents_Office_of_the_President_23102025-Archive.zip | 2026-09-03 | 2 |
| file sample | 8aacc30dac2ca9f41d7dd6d2913d94b0820f802bc04461ae65eb7cf70b53a8ab | 2026-03-03 | 1 |
| file sample | 8a7ee2a8e6b3476319a3a0d5846805fd25fa388c7f2215668bc134202ea093fa | 2026-03-03 | 1 |
| file sample | 3cbef162e14e74d1f95391091544b53deb23c41b41b8bbadd124209a63496424 | 2026-03-03 | 1 |
Detection coverage
- 193 YARA rules
- 807 Sigma rules
Malware & tools used
- Valid Accounts (attack-pattern)
- System Information Discovery (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- Permission Groups Discovery (attack-pattern)
- Wordlist Scanning (attack-pattern)
- PowerShell (attack-pattern)
- Rootkit (attack-pattern)
- Domain Account (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Windows Service (attack-pattern)
- File Transfer Protocols (attack-pattern)
- Remote System Discovery (attack-pattern)
- Software Packing (attack-pattern)
- Code Signing (attack-pattern)
- Scan Databases (attack-pattern)
- Tool (attack-pattern)
- Additional Local or Domain Groups (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- Local Account (attack-pattern)
- Bootkit (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Local Account (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- RedGolf (threat-actor)
Related threat objects
- APT17 (threat-actor)
- Winnti Group (threat-actor)
- RedGolf (threat-actor)
- BARIUM (threat-actor)
- LEAD (threat-actor)
Reports & references
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.com — Yir Cyber Threats Report Download (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- ESET — Exchange Servers Under Siege 10 Apt Groups (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- uscc.gov — Adam Kozy Testimony (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Kaspersky — 57585 (report)
- Kaspersky — 37029 (report)
- williamshowalter.com — A Universal Windows Bootkit (report)
- Microsoft — Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp (report)
- Kaspersky — 70991 (report)
- medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
- dw.com — A 36695341 (report)
- bleepingcomputer.com — Teamviewer Confirms Undisclosed Breach From 2016 (report)
- Trend Micro — Winnti Abuses Github (report)
- dw.com — A 48196004 (report)
- ESET — Gaming Industry Scope Attackers Asia (report)
- 401trg.com — Burning Umbrella (report)
- MITRE ATT&CK — G0044 (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For July Wicked Spider (report)
- secureworks.com — Bronze Atlas (report)
- secureworks.com — Bronze Export (report)
- justice.gov — Seven International Cyber Defendants Including Apt41 Actors Charged Connection Computer (report)
Attributed from
- APT41 DUST (campaign)
- C0017 (campaign)
- Operation CuckooBees (campaign)
- TOUGHPROGRESS Campaign (campaign)
External references
- mitre-attack — G0096
- Wicked Panda
- APT41
- Brass Typhoon
- BARIUM
- Crowdstrike GTR2020 Mar 2020
- FireEye APT41 2019
- FireEye APT41 Aug 2019
- apt41_mandiant
- Microsoft Threat Actor Naming July 2023
- Group IB APT 41 June 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy