- Home
- APT groups
- APT41
APT group profile
APT41
Chinese group that combines state-sponsored espionage with operations for personal profit, active since at least 2012 against healthcare, telecommunications, technology, government and the video game industry.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
APT41 is a group that, according to Mandiant, conducts Chinese state-sponsored espionage and, in parallel, financially motivated operations for the personal gain of its members. This dual nature is uncommon among Chinese state actors: the same non-public arsenal used in espionage campaigns appears in intrusions against the video game industry, where the group has manipulated virtual currencies, stolen source code and code-signing certificates, and attempted to deploy ransomware.
MITRE ATT&CK places it as active since at least 2012, with targets in healthcare, telecommunications, technology, finance, education, retail and video games. Its espionage has aligned with China’s five-year development plans, and Mandiant also documents surveillance of individuals (call records at telecommunications carriers, hotel reservation systems). The group partially overlaps with what other vendors call BARIUM and Winnti.
In September 2020 the U.S. Department of Justice announced charges against five Chinese nationals associated with APT41 for intrusions into more than 100 organizations worldwide, including victims in Brazil and Chile. Also relevant to Latin America is the 2020 mass exploitation campaign, which according to FireEye/Mandiant reached organizations in Mexico. There are no public reports of victims in Colombia as of this review.
Notable campaigns
- 2019 — “Double Dragon” report. Mandiant documents the dual espionage and cybercrime operation, including software supply chain compromises (Mandiant).
- 2020 — Global exploitation campaign. Between January and March, APT41 attempted to exploit Citrix ADC/Gateway (CVE-2019-19781), Cisco RV320/RV325 routers and Zoho ManageEngine Desktop Central (CVE-2020-10189) at more than 75 FireEye customers in some twenty countries, including Mexico (FireEye/Mandiant).
- 2020 — DOJ indictments. Charges for intrusions against software, video game and telecommunications companies, universities and foreign governments, and for the use of ransomware and cryptomining to monetize access (DOJ).
- 2021–2022 — U.S. state governments. Compromise of at least six state networks through exposed web applications, including a zero-day in USAHerds (CVE-2021-44207) and Log4j (CVE-2021-44228) (Mandiant).
- 2023–2024 — APT41 DUST. Prolonged access in maritime logistics, media and entertainment, technology and automotive, mainly in Italy, Spain, Taiwan, Thailand, Turkey and the United Kingdom, with DUSTPAN, DUSTTRAP and exfiltration to OneDrive (Mandiant / Google TAG).
- 2024–2025 — TOUGHPROGRESS. Spearphishing with links to files hosted on a compromised government site and use of Google Calendar as a command-and-control channel (GTIG).
- 2025 — Southern Africa. Espionage against government IT services with initial access through an exposed web server and C2 over an internal SharePoint (Kaspersky).
Key TTPs
Initial access. The most consistent vector is exploitation of internet-facing applications (T1190), with rapid adoption of newly published vulnerabilities. It also uses spearphishing with attachments (T1566.001) and links, software supply chain compromises (T1195.002), third-party VPN access (T1133) and valid credentials (T1078).
Execution and persistence. PowerShell (T1059.001) and WMI (T1047) for execution; web shells such as China Chopper (T1505.003), Windows services (T1543.003), scheduled tasks (T1053.005) and, in isolated cases, bootkits such as ROCKBOOT (T1542.003).
Defense evasion. DLL side-loading (T1574.001) and malware signed with stolen certificates (T1553.002), which reduces the effectiveness of reputation-based controls.
Credentials and lateral movement. Dumping of LSASS (T1003.001) and NTDS (T1003.003), pass-the-hash (T1550.002) and movement via SMB shares (T1021.002).
Collection, C2 and exfiltration. Database extraction (T1213.006), tool download with certutil and BITSAdmin (T1105), use of legitimate services as resolvers (T1102.001), proxies and CDNs to conceal C2 (T1090), and exfiltration to cloud storage (T1567.002).
Impact (financial side). Ransomware encryption (T1486) and cryptocurrency mining on victim resources (T1496.001).
Detection and mitigation
- Exposed attack surface. Inventory and prioritize patching of VPNs, ADCs, management consoles and public web applications (
M1051,M1016). When active exploitation advisories are issued, retroactively review WAF, reverse proxy and device logs from the CVE publication date onward. - Web shells. Monitor the creation of
.aspx,.jspand.phpfiles in web directories and child processes ofw3wp.exe,tomcatorhttpdthat launchcmd.exe,powershell.exeorcertutil.exe(Sysmon EID 1 and 11, or EDR telemetry). - LOLBins. Alert on
certutil -urlcache, BITS jobs to new domains andrundll32with DLLs outside system paths. Restrict their use with application control policies (M1038). - Credentials. Enable LSA Protection and Credential Guard (
M1043), monitor access tolsass.exe(Sysmon EID 10) and the creation of copies ofntds.dit. Enforce MFA on VPN and third-party remote access (M1032) and segment privileged accounts (M1026). - C2 over legitimate services. Correlate traffic to Google Calendar APIs, Cloudflare Workers, OneDrive or free hosting from servers that do not normally use them. Apply egress filtering on servers (
M1037). - Supply chain. Validate the integrity and signature of software updates and watch for binaries signed with revoked or unusual certificates.
- Hunting in the region. In the government, telecommunications, healthcare and video game sectors, look for miner activity (CPU spikes, connections to pools) and execution of
whoami,net groupandnetstatfrom web service accounts, early indicators of an intrusion of this kind.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Initial Access
Execution
Persistence
Defense Impairment
- T1553.002 Subvert Trust Controls: Code Signing
Credential Access
Lateral Movement
Collection
- T1213.006 Data from Information Repositories: Databases
Command and Control
Exfiltration
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Malware and tools
References
Public sources this profile is based on.
- [1] APT41, Wicked Panda, Brass Typhoon, BARIUM, Group G0096 · MITRE ATT&CK
- [2] APT41: A Dual Espionage and Cyber Crime Operation · Mandiant (FireEye), Aug 2019
- [3] This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits · Mandiant (FireEye), Mar 2020
- [4] Seven International Cyber Defendants, Including "APT41" Actors, Charged in Connection with Computer Intrusion Campaigns · U.S. Department of Justice, Sep 2020
- [5] Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments · Mandiant, Mar 2022
- [6] APT41 Has Arisen From the DUST · Mandiant / Google TAG, Jul 2024
- [7] Mark Your Calendar: APT41 Innovative Tactics · Google Threat Intelligence Group, May 2025
- [8] APT41 targets Southern African organization in espionage attack · Kaspersky, Jul 2025
Profile last updated: