APT41

MITRE ATT&CK: G0096 View on attack.mitre.org

Aliases: Wicked Panda, Brass Typhoon, BARIUM, TA415, Blackfly, Grayfly, LEAD, WICKED SPIDER, WICKED PANDA, BRONZE ATLAS, BRONZE EXPORT, Red Kelpie, Earth Baku, Amoeba, HOODOO, Winnti, Double Dragon, TG-2633, Leopard Typhoon, APT41, TG-3279, Mana, KAOS, Red Diablo, Winnti Group

First seen
2012-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state, criminal
Related IoCs
7 (4 malicious)
Last IoC activity
2026-09-03 02:19:48
Profile updated
2026-07-07 12:32:29

Targeted industries: education-and-nonprofits financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:us country_code:de country_code:jp country_code:au country_code:ca country_code:uk country_code:it country_code:fr country_code:ru country_code:in country_code:kr country_code:br country_code:mx country_code:id

Context

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to APT41 (G0096). The 4 most recently updated:

Detection coverage

  • 193 YARA rules
  • 807 Sigma rules

Malware & tools used

  • Valid Accounts (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Compromise Software Supply Chain (attack-pattern)
  • Permission Groups Discovery (attack-pattern)
  • Wordlist Scanning (attack-pattern)
  • PowerShell (attack-pattern)
  • Rootkit (attack-pattern)
  • Domain Account (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Windows Service (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Code Signing (attack-pattern)
  • Scan Databases (attack-pattern)
  • Tool (attack-pattern)
  • Additional Local or Domain Groups (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Local Account (attack-pattern)
  • Bootkit (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Local Account (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.com — Yir Cyber Threats Report Download (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • uscc.gov — Adam Kozy Testimony (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Kaspersky — 57585 (report)
  • Kaspersky — 37029 (report)
  • williamshowalter.com — A Universal Windows Bootkit (report)
  • Microsoft — Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp (report)
  • Kaspersky — 70991 (report)
  • medium.com — Winnti More Than Just Windows And Gates E4F03436031A (report)
  • dw.com — A 36695341 (report)
  • bleepingcomputer.com — Teamviewer Confirms Undisclosed Breach From 2016 (report)
  • Trend Micro — Winnti Abuses Github (report)
  • dw.com — A 48196004 (report)
  • ESET — Gaming Industry Scope Attackers Asia (report)
  • 401trg.com — Burning Umbrella (report)
  • MITRE ATT&CK — G0044 (report)
  • CrowdStrike — Meet Crowdstrikes Adversary Of The Month For July Wicked Spider (report)
  • secureworks.com — Bronze Atlas (report)
  • secureworks.com — Bronze Export (report)
  • justice.gov — Seven International Cyber Defendants Including Apt41 Actors Charged Connection Computer (report)

Attributed from

  • APT41 DUST (campaign)
  • C0017 (campaign)
  • Operation CuckooBees (campaign)
  • TOUGHPROGRESS Campaign (campaign)

External references