Skip to content
ChinaState-SponsoredActiveMITRE G0096Malpedia ↗

APT41

State espionage by day, cybercrime by night. Indicted operators ran MSS-aligned intrusions and personal money-making schemes from the same infrastructure.

Open MITRE Navigator layer ↗Download profile JSON
Active
2012–present
Motivation
Espionage, Financial Gain, IP Theft
Aliases
12
Exploited CVEs
6
ATT&CK techniques
12
Cited sources
12

Overview

APT41 is the definitive case study in the blurred line between Chinese state operations and private criminal enterprise.

Mandiant named it "Double Dragon" because it does two jobs at once. The same operators conduct espionage aligned with PRC strategic priorities — healthcare, telecommunications, semiconductors, and high-tech — while separately monetising their access through video game industry crime: virtual currency manipulation, in-game item theft, and ransomware deployment. Forensic timeline analysis shows espionage activity during Chinese business hours and gaming-related theft late at night, using the same certificates and infrastructure.

The group is the most prolific supply-chain attacker attributed to China. It has compromised software vendors to reach their customers repeatedly, including through the NetSarang/ShadowPad and CCleaner incidents, and stolen code-signing certificates from gaming companies to sign malware used in unrelated espionage operations.

U.S. indictments in August and September 2020 charged five Chinese nationals connected to Chengdu 404 Network Technology — a company that publicly presented itself as a legitimate security firm while, per the charging documents, conducting intrusions into more than 100 organisations worldwide. One defendant, Tan Dailin, had been publicly known as a hacker since 2006. Two Malaysian businessmen were separately charged for monetising the gaming-industry access.

The group remains active. In 2021 it exploited Log4Shell and a USAHERDS zero-day against at least six U.S. state government networks, and in 2022 the U.S. Secret Service attributed the theft of more than $20 million in COVID-19 relief funds to APT41-linked operators.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS), via contractor Chengdu 404 Network TechnologyConfirmed

Five Chinese nationals were indicted by the U.S. Department of Justice in August and September 2020, charged with intrusions into more than 100 companies worldwide. Charging documents identify Chengdu 404 Network Technology Co. Ltd. as the operating front, and describe defendant Jiang Lizhi discussing his connections to the Ministry of State Security and claiming political protection. Two Malaysian nationals were separately charged for monetising access to video game companies.

Attributing sources

Cross-vendor naming crosswalk

12 designators across 9 organisations.

4 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • APT41

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Brass TyphoonFormerly BARIUM
  • BARIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Wicked Panda

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT41
  • Double Dragon

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE ATLAS

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Kaspersky GReAT

index ↗
  • Winntipartial'Winnti' names a malware family used by several distinct Chinese groups — a persistent source of attribution error

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth BakupartialTrend Micro's cluster for a subset of APT41 activity

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Symantec (Broadcom)

index ↗
  • GrayflypartialSymantec splits the espionage element (Grayfly) from the financially motivated element (Blackfly)
  • BlackflypartialThe gaming-industry and financially motivated element

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • APT41

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomFranceIndiaJapanSouth KoreaTaiwanAustraliaSingaporeTürkiye

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

ShadowPadbackdoor

Modular backdoor delivered through supply-chain compromises; now shared across multiple Chinese state-nexus groups.

Malpedia ↗
Winntibackdoor

Rootkit-enabled implant family with a distinctive kernel driver, historically the group's signature tool.

Malpedia ↗
MESSAGETAPmalware

Linux implant on telecom SMS gateways that filters live SMS traffic by keyword, phone number, and IMSI.

DUSTPAN / DUSTTRAPloader

In-memory dropper chain executing payloads without touching disk.

KEYPLUGbackdoor

Modular backdoor with Windows and Linux variants supporting multiple C2 transports including WSS and KCP.

Malpedia ↗
LOWKEYbackdoor

Passive backdoor listening on IIS with a bespoke protocol, used for long-term persistence on public-facing servers.

Shared, commodity & living-off-the-land

Cobalt Strikeframework

Heavily customised profiles, in some cases with Beacon staged through hundreds of malleable configurations.

Stolen code-signing certificatesutility

Certificates stolen from gaming companies reused to sign malware in unrelated espionage operations.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT41
CVE-2022-47966KEVransomware9.81 Feb 2023Zoho ManageEngine unauthenticated RCE exploited for access to enterprise networks.SRCMandiant
CVE-2021-44228KEVransomware10.013 Dec 2021Log4Shell exploited within days of public disclosure against U.S. state government networks, alongside a USAHERDS zero-day — an unusually fast pivot from disclosure to operational use.SRCMandiant
CVE-2021-26855KEVransomware9.81 Mar 2021ProxyLogon exploitation of Exchange servers following the HAFNIUM disclosure, when several Chinese groups adopted the chain simultaneously.SRCESET
CVE-2020-14882KEVransomware9.81 Oct 2020Oracle WebLogic console authentication bypass used for initial access to enterprise servers.SRCU.S. Department of Justice
CVE-2019-18935KEVransomware9.81 Apr 2020Telerik UI deserialisation exploited for web shell deployment on internet-facing ASP.NET applications.SRCMandiant / FireEye
CVE-2019-19781KEVransomware9.820 Jan 2020Citrix ADC traversal exploited in a global campaign spanning 20 countries within weeks of disclosure.SRCMandiant / FireEye

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 12 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
12 techniques across 6 tactics · 8 with actor-specific notes

Initial Access

3

Persistence

2

Defense Evasion

3

Command and Control

1

Impact

2

Campaign timeline

  1. U.S. State Government Intrusions

    Compromise of at least six U.S. state government networks via a USAHERDS zero-day and Log4Shell exploitation within days of disclosure, demonstrating unusually fast weaponisation of new vulnerabilities.

    CVE-2021-44228GovernmentHealthcare

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.