← threatfilter.dev / all groups / APT41
APT41
Also known as: Wicked Panda · Brass Typhoon · BARIUM
Overview
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
Targets
Automotive · Business · Cryptocurrency · Education · Energy · Finance · Healthcare · High-Tech · Intergovernmental · Media · Pharmaceuticals · Private sector · Retail · Services · Telecommunications · Travel
Regions
China · France · Hong Kong · India · Italy · Japan · Myanmar · Netherlands · Singapore · South Africa · South Korea · Switzerland · Thailand · Turkey · United Kingdom · United States
Capabilities
- Supply-chain compromise — ATT&CK T1195.002
- Exploitation of public-facing / client applications — ATT&CK T1190, T1203
- Custom malware/implant development — ATT&CK: 18 attributed custom malware families
TTPs — 82 techniques across 15 tactics
Reconnaissance
-
T1595.002Vulnerability Scanning -
T1595.003Wordlist Scanning -
T1596.005Scan Databases
Resource Development
-
T1588.002Tool
Initial Access
-
T1190Exploit Public-Facing Application -
T1195.002Compromise Software Supply Chain -
T1566.001Spearphishing Attachment
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.004Unix Shell -
T1203Exploitation for Client Execution -
T1569.002Service Execution
Persistence
-
T1037Boot or Logon Initialization Scripts -
T1098.007Additional Local or Domain Groups -
T1133External Remote Services -
T1136.001Local Account -
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Privilege Escalation
-
T1546.008Accessibility Features
Stealth
-
T1014Rootkit -
T1027Obfuscated Files or Information -
T1027.002Software Packing -
T1036.004Masquerade Task or Service -
T1036.005Match Legitimate Resource Name or Location -
T1055Process Injection -
T1070.003Clear Command History -
T1070.004File Deletion -
T1078Valid Accounts -
T1197BITS Jobs -
T1218.001Compiled HTML File -
T1218.011Rundll32 -
T1480.001Environmental Keying -
T1542.003Bootkit -
T1574.001DLL -
T1574.006Dynamic Linker Hijacking -
T1684.001Impersonation
Defense Impairment
-
T1112Modify Registry -
T1484.001Group Policy Modification -
T1553.002Code Signing -
T1599Network Boundary Bridging -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1003.003NTDS -
T1110Brute Force -
T1555Credentials from Password Stores -
T1555.003Credentials from Web Browsers
Discovery
-
T1012Query Registry -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1046Network Service Discovery -
T1049System Network Connections Discovery -
T1069Permission Groups Discovery -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1135Network Share Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares -
T1550.002Pass the Hash -
T1570Lateral Tool Transfer
Collection
-
T1005Data from Local System -
T1056.001Keylogging -
T1213.003Code Repositories -
T1560.001Archive via Utility
Command and Control
-
T1008Fallback Channels -
T1071.001Web Protocols -
T1071.002File Transfer Protocols -
T1071.004DNS -
T1090Proxy -
T1102.001Dead Drop Resolver -
T1104Multi-Stage Channels -
T1105Ingress Tool Transfer -
T1568.002Domain Generation Algorithms
Exfiltration
Impact
-
T1486Data Encrypted for Impact -
T1496.001Compute Hijacking
Tools & malware (32)
ASPXSpy · BITSAdmin · PlugX · Impacket · gh0st RAT · netstat · PowerSploit · ZxShell · KEYPLUG · Ping · LightSpy · DUSTPAN · Net · ipconfig · sqlmap · China Chopper · ShadowPad · MESSAGETAP · Mimikatz · certutil · njRAT · Empire · Cobalt Strike · pwdump · BLACKCOFFEE · MOPSLED · ROCKBOOT · dsquery · Winnti for Linux · DUSTTRAP · Derusbi · ftp
Reporting (3)
- How Microsoft names threat actors — Microsoft
- Big airline heist APT41 likely behind a third-party attack on Air India — Rostovcev, N
- 2020 Global Threat Report — Crowdstrike