Skip to content

APT group profile

APT41

Chinese group that combines state-sponsored espionage with operations for personal profit, active since at least 2012 against healthcare, telecommunications, technology, government and the video game industry.

MITRE G0096 EspionageFinancial LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Initial Access

  • T1078 Valid Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1566.001 Phishing: Spearphishing Attachment

Execution

  • T1047 Windows Management Instrumentation
  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1574.001 Hijack Execution Flow: DLL

Persistence

  • T1505.003 Server Software Component: Web Shell
  • T1542.003 Pre-OS Boot: Bootkit
  • T1543.003 Create or Modify System Process: Windows Service

Defense Impairment

  • T1553.002 Subvert Trust Controls: Code Signing

Credential Access

Lateral Movement

  • T1021.002 Remote Services: SMB/Windows Admin Shares
  • T1550.002 Use Alternate Authentication Material: Pass the Hash

Collection

  • T1213.006 Data from Information Repositories: Databases

Command and Control

Exfiltration

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Impact

  • T1486 Data Encrypted for Impact
  • T1496.001 Resource Hijacking: Compute Hijacking

Malware and tools

References

Public sources this profile is based on.

  1. [1] APT41, Wicked Panda, Brass Typhoon, BARIUM, Group G0096 · MITRE ATT&CK
  2. [2] APT41: A Dual Espionage and Cyber Crime Operation · Mandiant (FireEye), Aug 2019
  3. [3] This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits · Mandiant (FireEye), Mar 2020
  4. [4] Seven International Cyber Defendants, Including "APT41" Actors, Charged in Connection with Computer Intrusion Campaigns · U.S. Department of Justice, Sep 2020
  5. [5] Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments · Mandiant, Mar 2022
  6. [6] APT41 Has Arisen From the DUST · Mandiant / Google TAG, Jul 2024
  7. [7] Mark Your Calendar: APT41 Innovative Tactics · Google Threat Intelligence Group, May 2025
  8. [8] APT41 targets Southern African organization in espionage attack · Kaspersky, Jul 2025

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.