Home/Threat Actor/APT41
Threat Actor

APT41

apt41_wickedpanda · china · active since 2012

APT41 (Wicked Panda / Brass Typhoon / BARIUM / Winnti / Double Dragon / G0096) is a Chinese MSS-linked threat actor, publicly attributed via US DOJ indictments to Chengdu 404 Network Technology Co. Ltd., active since 2012 conducting parallel state-directed cyber-espionage and self-directed financially-motivated operations against healthcare, telecom, technology, video-game, government, and supply-chain targets in 30+ countries.

documented operations include the CCleaner, NetSarang ShadowPad, and ASUS ShadowHammer supply-chain compromises, the 2020 global Citrix/Zoho/Confluence exploitation campaign, mass ProxyLogon and Log4Shell exploitation, the C0017 US state government intrusions, the C0040 APT41 DUST shipping-and-logistics campaign, and the MoonBounce UEFI bootkit.

china confidence: high 24 aliases MITRE ATT&CK G0096 ↗

Profile

APT41 is a Chinese state-sponsored threat actor that uniquely blends government-directed cyber-espionage with self-directed financially-motivated operations, the "double dragon" model that gives the group its frequent vendor name. Active since at least 2012, APT41 is publicly linked by US DOJ indictments to Chengdu 404 Network Technology Co. Ltd., a Sichuan-based MSS contractor.

Five Chinese nationals associated with Chengdu 404 were indicted in 2020 alongside two Malaysian accomplices who laundered proceeds from cryptocurrency theft and video-game virtual-currency fraud. Espionage targeting aligns with PRC strategic priorities (Five-Year Plans, Made in China 2025), healthcare, semiconductors, telecom, higher education, government, defense. Parallel financially-motivated operations focus on gaming companies (in-game currency theft, cryptocurrency exchange targeting, ransomware deployment via Encryptor RaaS) and supply-chain weaponization for fraud.

APT41 is one of the most prolific exploiters of n-day vulnerabilities in public-facing infrastructure: rapid weaponization of Log4Shell (T1190 / CVE-2021-44228), ProxyLogon (CVE-2021-26855), Citrix ADC (CVE-2019-19781), Zoho ManageEngine (CVE-2020-10189), and Atlassian Confluence (CVE-2019-3396). Tradecraft includes DLL search-order hijacking, code-signing certificate theft and reuse, UEFI bootkits (MoonBounce), supply-chain weaponization (CCleaner, ASUS Live Update / ShadowHammer, NetSarang / ShadowPad), and increasing use of legitimate cloud infrastructure (Cloudflare Workers, Google Workspace, OneDrive) for C2 and exfiltration. The group's toolkit overlaps significantly with the broader Winnti umbrella (Winnti for Windows, Winnti for Linux, PlugX, ShadowPad, Derusbi) shared across several Chinese clusters.

Aliases

24
apt41wicked pandawickedpandabrass typhoonbariumwinntiwinnti groupwinnti umbrelladouble dragonbronze atlasearth bakuhoodooblackflygrayflyred kelpieaxiomleadgrefplayful dragonwinnti for windowsapt-c-49g0096apt 41apt-41

Notable Campaigns

13
2023-2024C0040, APT41 DUST Campaign
2022MoonBounce UEFI Bootkit Discovery
2021-2022C0017, US State Government Intrusions
2021APT41 World Tour Campaign (2021)
2021Air India / SITA Supply Chain Compromise
2021ProxyLogon Mass Exploitation (CVE-2021-26855)
2020-2021COVID-19 Research and Healthcare Targeting
2020Chengdu 404 Indictments (DOJ September 2020)
2020APT41 Global Intrusion Campaign (March 2020)
2019MESSAGETAP Telecom SMS Interception (2019)
2018-2019ASUS Live Update Supply Chain (ShadowHammer)
2017NetSarang ShadowPad Supply Chain Compromise
2017CCleaner Supply Chain Compromise

Attribution & Reporting

Attributed by
US Department of JusticeFBICISANSAMicrosoftMandiantFireEyeCrowdStrikeGroup-IBESETKasperskySymantecTrend MicroCybereasonDCSOHHS HC3VolexityPWCTalosInsikt GroupRecorded FutureGoogle Cloud Threat IntelligenceMandiant Advantage
Key reporting
reportFireEye / Mandiant: Double Dragon, APT41, a dual espionage and cyber crime operation (August 2019)
reportMandiant: APT41, A Dual Espionage and Cyber Crime Operation (full report, 2022)
reportMandiant: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits (March 2020)
reportMandiant: Does This Look Infected?, APT41 US State Governments Compromise (March 2022)
reportMandiant / Google Cloud TI: APT41 Has Arisen from the DUST (July 2024)
reportGroup-IB: APT41 World Tour 2021, A Closer Look
reportGroup-IB: ColunmTK APT41, Tools, Tactics, and Procedures
reportCrowdStrike: 2020 Global Threat Report (WICKED PANDA section)
reportDCSO CyTec: APT41, The Spy Who Failed to Encrypt Me
reportKaspersky: Operation ShadowHammer (ASUS Live Update Compromise, March 2019)
reportKaspersky: ShadowPad, New Backdoor Affects Hundreds of Large Businesses in Asia (2017)
reportKaspersky: MoonBounce, The Dark Side of UEFI Firmware (January 2022)
reportESET: Winnti Group Targeting Universities in Hong Kong (2020)
reportCybereason: Operation Soft Cell, Worldwide Campaign Against Telecom Providers (June 2019)
reportRecorded Future / Insikt Group: China-Linked Group RedEcho Targets the Indian Power Sector (February 2021)
reportUS DOJ Indictment 1:20-cr-00146 (Zhang Haoran, Tan Dailin), August 2020
reportUS DOJ Indictment 1:19-cr-00310 (Jiang Lizhi, Qian Chuan, Fu Qiang), August 2020
reportFBI Wanted Notice, APT 41 Group
reportHHS HC3: Threat Profile APT41 (Health Sector Cybersecurity Coordination Center)
reportHHS HC3: China-Based Threat Actor Profiles (TLP:CLEAR, August 2023)
reportNatto Thoughts: i-SOON, Another Company in the APT41 Network
reportTrend Micro: Earth Baku, An APT Group Targeting Indo-Pacific Countries

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)54/60 · 90%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin