{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt41",
    "slug": "apt41",
    "name": "APT41",
    "shortName": "APT41",
    "country": "China",
    "countryCode": "CN",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2012",
    "prominence": 93,
    "mitreGroupId": "G0096",
    "malpediaSlug": "apt41",
    "tagline": "State espionage by day, cybercrime by night. Indicted operators ran MSS-aligned intrusions and personal money-making schemes from the same infrastructure.",
    "bio": "APT41 is the definitive case study in the blurred line between Chinese state operations and private criminal enterprise.\n\nMandiant named it \"Double Dragon\" because it does two jobs at once. The same operators conduct espionage aligned with PRC strategic priorities — healthcare, telecommunications, semiconductors, and high-tech — while separately monetising their access through video game industry crime: virtual currency manipulation, in-game item theft, and ransomware deployment. Forensic timeline analysis shows espionage activity during Chinese business hours and gaming-related theft late at night, using the same certificates and infrastructure.\n\nThe group is the most prolific supply-chain attacker attributed to China. It has compromised software vendors to reach their customers repeatedly, including through the NetSarang/ShadowPad and CCleaner incidents, and stolen code-signing certificates from gaming companies to sign malware used in unrelated espionage operations.\n\nU.S. indictments in August and September 2020 charged five Chinese nationals connected to Chengdu 404 Network Technology — a company that publicly presented itself as a legitimate security firm while, per the charging documents, conducting intrusions into more than 100 organisations worldwide. One defendant, Tan Dailin, had been publicly known as a hacker since 2006. Two Malaysian businessmen were separately charged for monetising the gaming-industry access.\n\nThe group remains active. In 2021 it exploited Log4Shell and a USAHERDS zero-day against at least six U.S. state government networks, and in 2022 the U.S. Secret Service attributed the theft of more than $20 million in COVID-19 relief funds to APT41-linked operators.",
    "attribution": {
      "sponsor": "China",
      "service": "Ministry of State Security (MSS), via contractor Chengdu 404 Network Technology",
      "confidence": "confirmed",
      "summary": "Five Chinese nationals were indicted by the U.S. Department of Justice in August and September 2020, charged with intrusions into more than 100 companies worldwide. Charging documents identify Chengdu 404 Network Technology Co. Ltd. as the operating front, and describe defendant Jiang Lizhi discussing his connections to the Ministry of State Security and claiming political protection. Two Malaysian nationals were separately charged for monetising access to video game companies.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Seven International Cyber Defendants, Including 'APT41' Actors, Charged in Computer Intrusion Campaigns",
          "url": "https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer",
          "date": "2020-09-16"
        },
        {
          "org": "Mandiant / FireEye",
          "title": "Double Dragon: APT41, a dual espionage and cyber crime operation",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-dual-espionage-and-cyber-crime-operation",
          "date": "2019-08-07"
        }
      ]
    },
    "motivations": [
      "espionage",
      "financial-gain",
      "ip-theft"
    ],
    "targetSectors": [
      "Technology",
      "Healthcare",
      "Telecommunications",
      "Gaming",
      "Government",
      "Semiconductors",
      "Pharmaceuticals",
      "Manufacturing",
      "Education",
      "Financial Services",
      "Media & Journalism"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "France",
      "India",
      "Japan",
      "South Korea",
      "Taiwan",
      "Australia",
      "Singapore",
      "Türkiye"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "APT41",
        "url": "https://attack.mitre.org/groups/G0096/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Brass Typhoon",
        "correlation": "exact",
        "note": "Formerly BARIUM"
      },
      {
        "org": "microsoft",
        "name": "BARIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Wicked Panda",
        "url": "https://www.crowdstrike.com/adversaries/wicked-panda/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT41",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "Double Dragon",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "BRONZE ATLAS",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Grayfly",
        "correlation": "partial",
        "note": "Symantec splits the espionage element (Grayfly) from the financially motivated element (Blackfly)"
      },
      {
        "org": "symantec",
        "name": "Blackfly",
        "correlation": "partial",
        "note": "The gaming-industry and financially motivated element"
      },
      {
        "org": "kaspersky",
        "name": "Winnti",
        "correlation": "partial",
        "note": "'Winnti' names a malware family used by several distinct Chinese groups — a persistent source of attribution error"
      },
      {
        "org": "trendmicro",
        "name": "Earth Baku",
        "correlation": "partial",
        "note": "Trend Micro's cluster for a subset of APT41 activity"
      },
      {
        "org": "cisa",
        "name": "APT41",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "ShadowPad",
        "type": "backdoor",
        "custom": true,
        "description": "Modular backdoor delivered through supply-chain compromises; now shared across multiple Chinese state-nexus groups.",
        "malpediaSlug": "win.shadowpad"
      },
      {
        "name": "Winnti",
        "type": "backdoor",
        "custom": true,
        "description": "Rootkit-enabled implant family with a distinctive kernel driver, historically the group's signature tool.",
        "malpediaSlug": "win.winnti"
      },
      {
        "name": "MESSAGETAP",
        "type": "malware",
        "custom": true,
        "description": "Linux implant on telecom SMS gateways that filters live SMS traffic by keyword, phone number, and IMSI."
      },
      {
        "name": "DUSTPAN / DUSTTRAP",
        "type": "loader",
        "custom": true,
        "description": "In-memory dropper chain executing payloads without touching disk."
      },
      {
        "name": "KEYPLUG",
        "type": "backdoor",
        "custom": true,
        "description": "Modular backdoor with Windows and Linux variants supporting multiple C2 transports including WSS and KCP.",
        "malpediaSlug": "win.keyplug"
      },
      {
        "name": "Cobalt Strike",
        "type": "framework",
        "custom": false,
        "description": "Heavily customised profiles, in some cases with Beacon staged through hundreds of malleable configurations."
      },
      {
        "name": "Stolen code-signing certificates",
        "type": "utility",
        "custom": false,
        "description": "Certificates stolen from gaming companies reused to sign malware in unrelated espionage operations."
      },
      {
        "name": "LOWKEY",
        "type": "backdoor",
        "custom": true,
        "description": "Passive backdoor listening on IIS with a bespoke protocol, used for long-term persistence on public-facing servers."
      }
    ],
    "techniques": [
      {
        "tCode": "T1195.002",
        "name": "Supply Chain Compromise: Compromise Software Supply Chain",
        "tactic": "Initial Access",
        "note": "Multiple software vendors trojanised to reach downstream customers"
      },
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Rapid weaponisation — Citrix, Cisco, Zoho, and Log4Shell exploited within days of disclosure"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1553.002",
        "name": "Subvert Trust Controls: Code Signing",
        "tactic": "Defense Evasion",
        "note": "Stolen certificates from gaming companies"
      },
      {
        "tCode": "T1014",
        "name": "Rootkit",
        "tactic": "Defense Evasion",
        "note": "Winnti kernel driver"
      },
      {
        "tCode": "T1505.003",
        "name": "Server Software Component: Web Shell",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1546.008",
        "name": "Event Triggered Execution: Accessibility Features",
        "tactic": "Persistence",
        "note": "sethc.exe and utilman.exe replacement for pre-authentication access"
      },
      {
        "tCode": "T1574.002",
        "name": "Hijack Execution Flow: DLL Side-Loading",
        "tactic": "Defense Evasion",
        "note": "Signed legitimate executables used to load malicious DLLs"
      },
      {
        "tCode": "T1090.001",
        "name": "Proxy: Internal Proxy",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact",
        "note": "Ransomware deployed against gaming targets for personal profit"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "Virtual currency manipulation and COVID-19 relief fund theft"
      },
      {
        "tCode": "T1005",
        "name": "Data from Local System",
        "tactic": "Collection"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2021-12-13",
        "usage": "Log4Shell exploited within days of public disclosure against U.S. state government networks, alongside a USAHERDS zero-day — an unusually fast pivot from disclosure to operational use.",
        "source": {
          "org": "Mandiant",
          "title": "Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-us-state-governments",
          "date": "2022-03-08"
        }
      },
      {
        "cveId": "CVE-2019-19781",
        "firstExploited": "2020-01-20",
        "usage": "Citrix ADC traversal exploited in a global campaign spanning 20 countries within weeks of disclosure.",
        "source": {
          "org": "Mandiant / FireEye",
          "title": "This Is Not a Test: APT41 Initiates Global Intrusion Campaign",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-initiates-global-intrusion-campaign-using-multiple-exploits",
          "date": "2020-03-25"
        }
      },
      {
        "cveId": "CVE-2020-14882",
        "firstExploited": "2020-10-01",
        "usage": "Oracle WebLogic console authentication bypass used for initial access to enterprise servers.",
        "source": {
          "org": "U.S. Department of Justice",
          "title": "Indictment: US v. Zhang Haoran and Tan Dailin",
          "url": "https://www.justice.gov/opa/press-release/file/1317206/download",
          "date": "2020-09-16"
        }
      },
      {
        "cveId": "CVE-2022-47966",
        "firstExploited": "2023-02-01",
        "usage": "Zoho ManageEngine unauthenticated RCE exploited for access to enterprise networks.",
        "source": {
          "org": "Mandiant",
          "title": "APT41 tooling and infrastructure analysis",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-arisen-from-dust",
          "date": "2024-07-18"
        }
      },
      {
        "cveId": "CVE-2021-26855",
        "firstExploited": "2021-03-01",
        "usage": "ProxyLogon exploitation of Exchange servers following the HAFNIUM disclosure, when several Chinese groups adopted the chain simultaneously.",
        "source": {
          "org": "ESET",
          "title": "Exchange servers under siege from at least 10 APT groups",
          "url": "https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/",
          "date": "2021-03-10"
        }
      },
      {
        "cveId": "CVE-2019-18935",
        "firstExploited": "2020-04-01",
        "usage": "Telerik UI deserialisation exploited for web shell deployment on internet-facing ASP.NET applications.",
        "source": {
          "org": "Mandiant / FireEye",
          "title": "This Is Not a Test: APT41 Initiates Global Intrusion Campaign",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-initiates-global-intrusion-campaign-using-multiple-exploits",
          "date": "2020-03-25"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt10",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Both MSS-linked contractor operations; overlapping use of ShadowPad and shared certificate abuse patterns."
      },
      {
        "relatedActorId": "salt-typhoon",
        "type": "shared-tooling",
        "confidence": "moderate",
        "note": "Overlapping implant families consistent with a shared PRC contractor supply chain."
      },
      {
        "relatedActorId": "apt40",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both MSS-aligned contractor operations with distinct regional taskings."
      }
    ],
    "reports": [
      {
        "org": "Mandiant / FireEye",
        "title": "Double Dragon: APT41, a Dual Espionage and Cyber Crime Operation",
        "url": "https://services.google.com/fh/files/misc/apt41-dual-espionage-and-cyber-crime-operation.pdf",
        "date": "2019-08-07"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Seven International Cyber Defendants Charged — APT41 / Chengdu 404",
        "url": "https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer",
        "date": "2020-09-16"
      },
      {
        "org": "Mandiant",
        "title": "APT41 Has Arisen From the DUST",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-arisen-from-dust",
        "date": "2024-07-18"
      },
      {
        "org": "Mandiant / FireEye",
        "title": "MESSAGETAP: Who's Reading Your Text Messages?",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/messagetap-who-is-reading-your-text-messages",
        "date": "2019-10-31"
      }
    ],
    "campaigns": [
      {
        "id": "apt41-state-gov",
        "actorId": "apt41",
        "name": "U.S. State Government Intrusions",
        "date": "2021-05-01",
        "endDate": "2022-02-01",
        "significance": "major",
        "targetSectors": [
          "Government",
          "Healthcare"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [
          "CVE-2021-44228"
        ],
        "summary": "Compromise of at least six U.S. state government networks via a USAHERDS zero-day and Log4Shell exploitation within days of disclosure, demonstrating unusually fast weaponisation of new vulnerabilities.",
        "sources": [
          {
            "org": "Mandiant",
            "title": "Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments",
            "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt41-us-state-governments",
            "date": "2022-03-08"
          }
        ]
      }
    ],
    "flag": "🇨🇳",
    "profile": "/apt/apt41/"
  }
}