APT41
Also tracked as Wicked Panda, Brass Typhoon, BARIUM
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
- Documented techniques
- 82
- Assessed origin
- China
- Assessed motivation
- Espionage
- First seen
- 2012
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development1
initial access3
execution7
persistence6
privilege escalation1
credential access6
discovery12
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1069 Permission Groups Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1135 Network Share Discovery
lateral movement4
collection4
command and control9
exfiltration1
defense impairment6
stealth17
- T1014 Rootkit
- T1027 Obfuscated Files or Information
- T1027.002 Software Packing
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1055 Process Injection
- T1070.003 Clear Command History
- T1070.004 File Deletion
- T1078 Valid Accounts
- T1197 BITS Jobs
- T1218.001 Compiled HTML File
- T1218.011 Rundll32
- T1480.001 Environmental Keying
- T1542.003 Bootkit
- T1574.001 DLL
- T1574.006 Dynamic Linker Hijacking
- T1684.001 Impersonation
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.