Saltar al contenido

Perfil de grupo APT

APT41

Grupo chino que combina espionaje patrocinado por el Estado con operaciones de lucro propio, activo desde al menos 2012 contra salud, telecomunicaciones, tecnología, gobierno y la industria de videojuegos.

MITRE G0096 EspionajeFinanciera Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Acceso inicial

  • T1078 Valid Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
  • T1566.001 Phishing: Spearphishing Attachment

Ejecución

  • T1047 Windows Management Instrumentation
  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1574.001 Hijack Execution Flow: DLL

Persistencia

  • T1505.003 Server Software Component: Web Shell
  • T1542.003 Pre-OS Boot: Bootkit
  • T1543.003 Create or Modify System Process: Windows Service

Debilitamiento de defensas

  • T1553.002 Subvert Trust Controls: Code Signing

Acceso a credenciales

Movimiento lateral

  • T1021.002 Remote Services: SMB/Windows Admin Shares
  • T1550.002 Use Alternate Authentication Material: Pass the Hash

Recolección

  • T1213.006 Data from Information Repositories: Databases

Comando y control

Exfiltración

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Impacto

  • T1486 Data Encrypted for Impact
  • T1496.001 Resource Hijacking: Compute Hijacking

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] APT41, Wicked Panda, Brass Typhoon, BARIUM, Group G0096 · MITRE ATT&CK
  2. [2] APT41: A Dual Espionage and Cyber Crime Operation · Mandiant (FireEye), ago. 2019
  3. [3] This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits · Mandiant (FireEye), mar. 2020
  4. [4] Seven International Cyber Defendants, Including "APT41" Actors, Charged in Connection with Computer Intrusion Campaigns · U.S. Department of Justice, sep. 2020
  5. [5] Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments · Mandiant, mar. 2022
  6. [6] APT41 Has Arisen From the DUST · Mandiant / Google TAG, jul. 2024
  7. [7] Mark Your Calendar: APT41 Innovative Tactics · Google Threat Intelligence Group, may. 2025
  8. [8] APT41 targets Southern African organization in espionage attack · Kaspersky, jul. 2025

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.