LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

EnterpriseG0096GroupObject v4.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0096: APT41 describes [APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of...

Executive priority

G0096: APT41 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0096: APT41 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0096: APT41 appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

57 rows
DomainIDNameRelationship / procedure
EnterpriseT1078Valid Accounts

APT41 used compromised credentials to log on to other systems.[2][4]

EnterpriseT1082System Information Discovery

APT41 uses multiple built-in commands such as systeminfo and `net config Workstation` to enumerate victim system basic configuration information.CitationRostovcev APT41 2021

EnterpriseT1195.002Compromise Software Supply ChainSub-technique

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.[2]

EnterpriseT1069Permission Groups Discovery

APT41 used net group commands to enumerate various Windows user groups and permissions.CitationRostovcev APT41 2021

EnterpriseT1595.003Wordlist ScanningSub-technique

APT41 leverages various tools and frameworks to brute-force directories on web servers.CitationRostovcev APT41 2021

EnterpriseT1059.001PowerShellSub-technique

APT41 leveraged PowerShell to deploy malware families in victims’ environments.[2]CitationFireEye APT41 March 2020

EnterpriseT1014Rootkit

APT41 deployed rootkits on Linux systems.[2][4]

EnterpriseT1087.002Domain AccountSub-technique

APT41 used built-in net commands to enumerate domain administrator users.CitationRostovcev APT41 2021

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.CitationRostovcev APT41 2021

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

APT41 attempted to masquerade their files as popular anti-virus software.[2][3]

EnterpriseT1543.003Windows ServiceSub-technique

APT41 modified legitimate Windows services to install malware backdoors.[2][3] APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.CitationFireEye APT41 March 2020

EnterpriseT1071.002File Transfer ProtocolsSub-technique

APT41 used exploit payloads that initiate download via ftp.CitationFireEye APT41 March 2020

EnterpriseT1018Remote System Discovery

APT41 has used MiPing to discover active systems in the victim network.Citationapt41_dcsocytec_dec2022

EnterpriseT1027.002Software PackingSub-technique

APT41 uses packers such as Themida to obfuscate malicious files.CitationRostovcev APT41 2021

EnterpriseT1553.002Code SigningSub-technique

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.[2][3]

EnterpriseT1596.005Scan DatabasesSub-technique

APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims.CitationRostovcev APT41 2021

EnterpriseT1588.002ToolSub-technique

APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.[2]

EnterpriseT1098.007Additional Local or Domain GroupsSub-technique

APT41 has added user accounts to the User and Admin groups.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).[4]Citationapt41_dcsocytec_dec2022

EnterpriseT1037Boot or Logon Initialization Scripts

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.[1]

EnterpriseT1136.001Local AccountSub-technique

APT41 has created user accounts.[2]

EnterpriseT1542.003BootkitSub-technique

APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems.[2]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.[2]

EnterpriseT1087.001Local AccountSub-technique

APT41 used built-in net commands to enumerate local administrator groups.CitationRostovcev APT41 2021

EnterpriseT1071.001Web ProtocolsSub-technique

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.CitationFireEye APT41 March 2020

EnterpriseT1135Network Share Discovery

APT41 used the net share command as part of network reconnaissance.[2][3]

EnterpriseT1599Network Boundary Bridging

APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP.Citationapt41_dcsocytec_dec2022

EnterpriseT1480.001Environmental KeyingSub-technique

APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number.CitationTwitter ItsReallyNick APT41 EK

EnterpriseT1484.001Group Policy ModificationSub-technique

APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware.[1]

EnterpriseT1595.002Vulnerability ScanningSub-technique

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.CitationRostovcev APT41 2021

EnterpriseT1005Data from Local System

APT41 has uploaded files and data from a compromised host.[3]

EnterpriseT1133External Remote Services

APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service.[2]

EnterpriseT1070.004File DeletionSub-technique

APT41 deleted files from the system.[2]CitationRostovcev APT41 2021

EnterpriseT1566.001Spearphishing AttachmentSub-technique

APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.[2]

EnterpriseT1685Disable or Modify Tools

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.CitationRostovcev APT41 2021

EnterpriseT1053.005Scheduled TaskSub-technique

APT41 used a compromised account to create a scheduled task on a system.[2][4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

APT41 created and modified startup files for persistence.[2][3] APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.CitationFireEye APT41 March 2020

EnterpriseT1546.008Accessibility FeaturesSub-technique

APT41 leveraged sticky keys to establish persistence.[2]

EnterpriseT1110Brute Force

APT41 performed password brute-force attacks on the local admin account.[2]

EnterpriseT1550.002Pass the HashSub-technique

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.CitationRostovcev APT41 2021

EnterpriseT1574.006Dynamic Linker HijackingSub-technique

APT41 has configured payloads to load via LD_PRELOAD.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

APT41 used cmd.exe /c to execute commands on remote machines.[2] APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.CitationFireEye APT41 March 2020

EnterpriseT1003.002Security Account ManagerSub-technique

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.CitationRostovcev APT41 2021

EnterpriseT1568.002Domain Generation AlgorithmsSub-technique

APT41 has used DGAs to change their C2 servers monthly.[2]

EnterpriseT1569.002Service ExecutionSub-technique

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.CitationFireEye APT41 March 2020[3]

EnterpriseT1071.004DNSSub-technique

APT41 used DNS for C2 communications.[2][3]

EnterpriseT1046Network Service Discovery

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.[2]

EnterpriseT1560.001Archive via UtilitySub-technique

APT41 created a RAR archive of targeted files for exfiltration.[2] Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.Citationapt41_dcsocytec_dec2022

EnterpriseT1218.011Rundll32Sub-technique

APT41 has used rundll32.exe to execute a loader.[4]

EnterpriseT1102.001Dead Drop ResolverSub-technique

APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet.[2]

EnterpriseT1008Fallback Channels

APT41 used the Steam community page as a fallback mechanism for C2.[2]

EnterpriseT1555Credentials from Password Stores

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.CitationRostovcev APT41 2021

EnterpriseT1496.001Compute HijackingSub-technique

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.[2][1]

EnterpriseT1003.003NTDSSub-technique

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.CitationRostovcev APT41 2021

EnterpriseT1049System Network Connections Discovery

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.[2][3]

EnterpriseT1059.004Unix ShellSub-technique

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.CitationFireEye APT41 March 2020

EnterpriseT1486Data Encrypted for Impact

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user.[2] APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.Citationapt41_dcsocytec_dec2022

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0104: netstat

netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics. [1]

ToolEnterprise

S0194: PowerSploit

PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]

Windows
MalwareEnterprise

S0412: ZxShell

ZxShell is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites. It has been used since at least 2004.[1][2]

Windows
MalwareEnterprise

S1051: KEYPLUG

KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021.[1]

LinuxWindows
ToolEnterprise

S0097: Ping

Ping is an operating system utility commonly used to troubleshoot and verify network connections. [1]

MalwareEnterprise

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
4.2
Created
Modified
Raw hash
f7c1d29390a7f6f6...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.24.2Current bundlef7c1d29390a7…
19.14.2Older bundle2aa901da2e5b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    apt41_mandiant

    Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.

    Open source URL
  2. [2]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  3. [3]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  4. [4]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  5. [5]
    APT41

    (Citation: FireEye APT41 2019)

  6. [6]
    BARIUM

    (Citation: Microsoft Threat Actor Naming July 2023)

  7. [7]
    Brass Typhoon

    (Citation: Microsoft Threat Actor Naming July 2023)

  8. [8]
    FireEye APT41 2019

    FireEye. (2019). Double DragonAPT41, a dual espionage andcyber crime operationAPT41. Retrieved September 23, 2019.

    Open source URL
  9. [9]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  10. [10]
    Wicked Panda

    (Citation: Crowdstrike GTR2020 Mar 2020)

  11. [11]
    mitre-attackG0096
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.