G0096: APT41
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]
Security context for executives and security teams
G0096: APT41 describes [APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of...
Executive priority
G0096: APT41 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0096: APT41 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0096: APT41 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
APT41
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1078 | Valid Accounts | |
| Enterprise | T1082 | System Information Discovery | APT41 uses multiple built-in commands such as |
| Enterprise | T1195.002 | Compromise Software Supply ChainSub-technique | |
| Enterprise | T1069 | Permission Groups Discovery | APT41 used |
| Enterprise | T1595.003 | Wordlist ScanningSub-technique | APT41 leverages various tools and frameworks to brute-force directories on web servers.CitationRostovcev APT41 2021 |
| Enterprise | T1059.001 | PowerShellSub-technique | |
| Enterprise | T1014 | Rootkit | |
| Enterprise | T1087.002 | Domain AccountSub-technique | APT41 used built-in |
| Enterprise | T1555.003 | Credentials from Web BrowsersSub-technique | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.CitationRostovcev APT41 2021 |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | |
| Enterprise | T1543.003 | Windows ServiceSub-technique | APT41 modified legitimate Windows services to install malware backdoors.[2][3] APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.CitationFireEye APT41 March 2020 |
| Enterprise | T1071.002 | File Transfer ProtocolsSub-technique | |
| Enterprise | T1018 | Remote System Discovery | APT41 has used MiPing to discover active systems in the victim network.Citationapt41_dcsocytec_dec2022 |
| Enterprise | T1027.002 | Software PackingSub-technique | APT41 uses packers such as Themida to obfuscate malicious files.CitationRostovcev APT41 2021 |
| Enterprise | T1553.002 | Code SigningSub-technique | |
| Enterprise | T1596.005 | Scan DatabasesSub-technique | APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims.CitationRostovcev APT41 2021 |
| Enterprise | T1588.002 | ToolSub-technique | APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.[2] |
| Enterprise | T1098.007 | Additional Local or Domain GroupsSub-technique | |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1037 | Boot or Logon Initialization Scripts | |
| Enterprise | T1136.001 | Local AccountSub-technique | |
| Enterprise | T1542.003 | BootkitSub-technique | |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | |
| Enterprise | T1087.001 | Local AccountSub-technique | APT41 used built-in |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.CitationFireEye APT41 March 2020 |
| Enterprise | T1135 | Network Share Discovery | |
| Enterprise | T1599 | Network Boundary Bridging | APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP.Citationapt41_dcsocytec_dec2022 |
| Enterprise | T1480.001 | Environmental KeyingSub-technique | APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number.CitationTwitter ItsReallyNick APT41 EK |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.CitationRostovcev APT41 2021 |
| Enterprise | T1005 | Data from Local System | |
| Enterprise | T1133 | External Remote Services | |
| Enterprise | T1070.004 | File DeletionSub-technique | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1685 | Disable or Modify Tools | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.CitationRostovcev APT41 2021 |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | APT41 created and modified startup files for persistence.[2][3] APT41 added a registry key in |
| Enterprise | T1546.008 | Accessibility FeaturesSub-technique | |
| Enterprise | T1110 | Brute Force | |
| Enterprise | T1550.002 | Pass the HashSub-technique | |
| Enterprise | T1574.006 | Dynamic Linker HijackingSub-technique | |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | APT41 used |
| Enterprise | T1003.002 | Security Account ManagerSub-technique | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| Enterprise | T1568.002 | Domain Generation AlgorithmsSub-technique | |
| Enterprise | T1569.002 | Service ExecutionSub-technique | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.CitationFireEye APT41 March 2020[3] |
| Enterprise | T1071.004 | DNSSub-technique | |
| Enterprise | T1046 | Network Service Discovery | |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | |
| Enterprise | T1218.011 | Rundll32Sub-technique | |
| Enterprise | T1102.001 | Dead Drop ResolverSub-technique | |
| Enterprise | T1008 | Fallback Channels | |
| Enterprise | T1555 | Credentials from Password Stores | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.CitationRostovcev APT41 2021 |
| Enterprise | T1496.001 | Compute HijackingSub-technique | |
| Enterprise | T1003.003 | NTDSSub-technique | APT41 used ntdsutil to obtain a copy of the victim environment |
| Enterprise | T1049 | System Network Connections Discovery | |
| Enterprise | T1059.004 | Unix ShellSub-technique | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.CitationFireEye APT41 March 2020 |
| Enterprise | T1486 | Data Encrypted for Impact |
Groups, software, and campaigns
S0073: ASPXSpy
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. [1]
S0190: BITSAdmin
S0013: PlugX
S0357: Impacket
S0032: gh0st RAT
S0104: netstat
S0194: PowerSploit
PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]
S0412: ZxShell
S1051: KEYPLUG
S0097: Ping
S1185: LightSpy
First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]
S1158: DUSTPAN
C0040: APT41 DUST
APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media for information gathering purposes. APT41 used previously-observed malware such as DUSTPAN as well as newly observed tools such as DUSTTRAP in APT41 DUST.[1]
C0017: C0017
C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 4.2 | Current bundle | f7c1d29390a7… | ||
| 19.1 | 4.2 | Older bundle | 2aa901da2e5b… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]apt41_mandiant
Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.
Open source URL - [2]FireEye APT41 Aug 2019
Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
Open source URL - [3]Group IB APT 41 June 2021
Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.
Open source URL - [4]Crowdstrike GTR2020 Mar 2020
Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
Open source URL - [5]APT41
(Citation: FireEye APT41 2019)
- [6]BARIUM
(Citation: Microsoft Threat Actor Naming July 2023)
- [7]Brass Typhoon
(Citation: Microsoft Threat Actor Naming July 2023)
- [8]FireEye APT41 2019
FireEye. (2019). Double DragonAPT41, a dual espionage andcyber crime operationAPT41. Retrieved September 23, 2019.
Open source URL - [9]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [10]Wicked Panda
(Citation: Crowdstrike GTR2020 Mar 2020)
- [11]mitre-attackG0096Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
