APT41 — APT Profile
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Wicked Panda, Brass Typhoon, BARIUM, Earth Baku, Earth Freybug
IntelFusions coverage (2)
- Hackers Hijack Palo Alto Firewalls With Unpatched Root Flaw 2026-06-06 · Nation-State
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16 · Nation-State
Tools & malware
- apk.dragonegg Mobile Malware
- apk.wyrmspy Mobile Malware
- ASPXSpy Web Shell
- BITSAdmin LOLBin
- BLACKCOFFEE Backdoor
- certutil LOLBin
- China Chopper Web Shell
- Cobalt Strike Adversary Simulation
- CUNNINGPIGEON Backdoor
- DEATHLOTUS Webshell
- Derusbi Backdoor
- dsquery Network Reconnaissance
- DUSTPAN Backdoor
- DUSTTRAP Backdoor
- elf.keyplug Backdoor
- elf.messagetap Network Sniffer
- Empire Post-Exploitation Framework
- ftp Exfiltration
- gh0st RAT Remote Access Trojan
- Impacket Network Toolkit
- ipconfig Network Reconnaissance
- KEYPLUG Backdoor
- LightSpy Mobile Malware
- MESSAGETAP Network Sniffer
- Mimikatz Credential Harvesting
- MOPSLED Backdoor
- Net Network Reconnaissance
- netstat Network Reconnaissance
- njRAT Remote Access Trojan
- NSDUMP Backdoor
- php.aspxspy Infostealer
- Ping Network Reconnaissance
- PlugX Backdoor
- PowerSploit Post-Exploitation Framework
- PRIVATELOG Loader
- pwdump Credential Harvesting
- ROCKBOOT Bootkit
- SHADOWGAZE Backdoor
- ShadowPad Backdoor
- sqlmap Exploitation Tool
- UNAPIMON Tool
- win.acehash Credential Harvesting
- win.biopass Backdoor
- win.blackcoffee Backdoor
- win.chinachopper Web Shell
- win.cobalt_strike Adversary Simulation
- win.coldlock Backdoor
- win.crackshot Backdoor
- win.crosswalk Backdoor
- win.dboxagent Backdoor
- win.derusbi Backdoor
- win.dusttrap Backdoor
- win.easynight Backdoor
- win.gearshift Backdoor
- win.godrat Remote Access Trojan
- win.highnoon Backdoor
- win.highnoon_bin Backdoor
- win.jumpall Backdoor
- win.lowkey Backdoor
- win.moonbounce UEFI Rootkit
Vendor research
- Double DragonAPT41, a dual espionage andcyber crime operationAPT41 FireEye
- Kaspersky MDR Kaspersky
- Operation CuckooBees: A Winnti Malware Arsenal Deep-Dive Cybereason
- Earth Freybug Uses UNAPIMON for Unhooking Critical APIs Trend Micro
- Stealth in the Shadows: Dissecting Earth Freybug's Recent Campaign and Operational Techniques (JSAC2025) Trend Micro
- How Microsoft names threat actors Microsoft
- Double DragonAPT41, a dual espionage andcyber crime operationAPT41 FireEye
- Big airline heist APT41 likely behind a third-party attack on Air India Group IB
- 2020 Global Threat Report Crowdstrike
Countries linked to this actor
- United States targets
- Italy targets
- South Africa targets
- Spain targets
- Indonesia targets
- Kazakhstan targets
- China origin
- Taiwan targets
- Singapore targets
- India targets
- Hong Kong targets
- Qatar targets
- Turkey targets