APT41
APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.
APT41 is a China-based dual threat actor known for state-sponsored espionage and financially motivated cyber operations.
APT41 is a highly prolific nation-state threat actor from China engaged in both state-sponsored espionage and financially motivated operations. It targets a wide range of sectors including automotive, healthcare, energy, high-tech, cryptocurrency, and media across multiple regions like Asia, Europe, and the Middle East. The group utilizes a combination of custom malware (Winnti, PlugX, PipeMon) and publicly available toolsets (Impacket, Mimikatz, PowerSploit, sqlmap) while employing TTPs such as acquiring infrastructure via domains and using code signing for defense impairment. Defenders must prioritize detecting code signing abuses, lateral movement via tools like Impacket and Mimikatz, and application-layer attacks leveraging sqlmap.
APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.
Monitor for newly registered domains that could be used for Command and Control or other malicious activities.
Monitor system calls and file system activity for signs of rootkit installation or suspicious behavior.
Monitor for unusual process enumeration and file/directory listing activities, especially when executed by unusual or unauthorized processes.
Inspect network traffic for unauthorized file transfers, especially those involving unexpected protocols or ports.
Verify the authenticity of code signatures and monitor for unexpected or unauthorized use of code signing certificates.
APT41 is known for carrying out both state-sponsored espionage and financially motivated operations.
Defenders must prioritize detecting code signing abuses, lateral movement via tools like Impacket and Mimikatz, and application-layer attacks leveraging sqlmap.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.