Initial Access
3 techniques·derived
Multiple software vendors trojanised to reach downstream customers. Rapid weaponisation — Citrix, Cisco, Zoho, and Log4Shell exploited within days of disclosure.
State espionage by day, cybercrime by night. Indicted operators ran MSS-aligned intrusions and personal money-making schemes from the same infrastructure.
APT41 is the definitive case study in the blurred line between Chinese state operations and private criminal enterprise.
Mandiant named it "Double Dragon" because it does two jobs at once. The same operators conduct espionage aligned with PRC strategic priorities — healthcare, telecommunications, semiconductors, and high-tech — while separately monetising their access through video game industry crime: virtual currency manipulation, in-game item theft, and ransomware deployment. Forensic timeline analysis shows espionage activity during Chinese business hours and gaming-related theft late at night, using the same certificates and infrastructure.
The group is the most prolific supply-chain attacker attributed to China. It has compromised software vendors to reach their customers repeatedly, including through the NetSarang/ShadowPad and CCleaner incidents, and stolen code-signing certificates from gaming companies to sign malware used in unrelated espionage operations.
U.S. indictments in August and September 2020 charged five Chinese nationals connected to Chengdu 404 Network Technology — a company that publicly presented itself as a legitimate security firm while, per the charging documents, conducting intrusions into more than 100 organisations worldwide. One defendant, Tan Dailin, had been publicly known as a hacker since 2006. Two Malaysian businessmen were separately charged for monetising the gaming-industry access.
The group remains active. In 2021 it exploited Log4Shell and a USAHERDS zero-day against at least six U.S. state government networks, and in 2022 the U.S. Secret Service attributed the theft of more than $20 million in COVID-19 relief funds to APT41-linked operators.
Down to the named unit where public evidence supports it.
Five Chinese nationals were indicted by the U.S. Department of Justice in August and September 2020, charged with intrusions into more than 100 companies worldwide. Charging documents identify Chengdu 404 Network Technology Co. Ltd. as the operating front, and describe defendant Jiang Lizhi discussing his connections to the Ministry of State Security and claiming political protection. Two Malaysian nationals were separately charged for monetising access to video game companies.
Attributing sources
12 designators across 9 organisations.
4 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Modular backdoor delivered through supply-chain compromises; now shared across multiple Chinese state-nexus groups.
Malpedia ↗Rootkit-enabled implant family with a distinctive kernel driver, historically the group's signature tool.
Malpedia ↗Linux implant on telecom SMS gateways that filters live SMS traffic by keyword, phone number, and IMSI.
In-memory dropper chain executing payloads without touching disk.
Modular backdoor with Windows and Linux variants supporting multiple C2 transports including WSS and KCP.
Malpedia ↗Passive backdoor listening on IIS with a bespoke protocol, used for long-term persistence on public-facing servers.
Shared, commodity & living-off-the-land
Heavily customised profiles, in some cases with Beacon staged through hundreds of malleable configurations.
Certificates stolen from gaming companies reused to sign malware in unrelated espionage operations.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT41 | ||
|---|---|---|---|---|
| CVE-2022-47966KEVransomware | 9.8 | Zoho ManageEngineZoho | 1 Feb 2023 | Zoho ManageEngine unauthenticated RCE exploited for access to enterprise networks.SRCMandiant ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 13 Dec 2021 | Log4Shell exploited within days of public disclosure against U.S. state government networks, alongside a USAHERDS zero-day — an unusually fast pivot from disclosure to operational use.SRCMandiant ↗ |
| CVE-2021-26855KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Mar 2021 | ProxyLogon exploitation of Exchange servers following the HAFNIUM disclosure, when several Chinese groups adopted the chain simultaneously.SRCESET ↗ |
| CVE-2020-14882KEVransomware | 9.8 | Oracle WebLogic ServerOracle | 1 Oct 2020 | Oracle WebLogic console authentication bypass used for initial access to enterprise servers.SRCU.S. Department of Justice ↗ |
| CVE-2019-18935KEVransomware | 9.8 | Telerik UI for ASP.NET AJAXProgress Software | 1 Apr 2020 | Telerik UI deserialisation exploited for web shell deployment on internet-facing ASP.NET applications.SRCMandiant / FireEye ↗ |
| CVE-2019-19781KEVransomware | 9.8 | Citrix ADC / GatewayCitrix | 20 Jan 2020 | Citrix ADC traversal exploited in a global campaign spanning 20 countries within weeks of disclosure.SRCMandiant / FireEye ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
3 techniques·derived
Multiple software vendors trojanised to reach downstream customers. Rapid weaponisation — Citrix, Cisco, Zoho, and Log4Shell exploited within days of disclosure.
2 techniques·derived
sethc.exe and utilman.exe replacement for pre-authentication access.
3 techniques·derived
Stolen certificates from gaming companies. Winnti kernel driver. Signed legitimate executables used to load malicious DLLs.
1 technique·derived
Data from Local System.
1 technique·derived
Internal Proxy.
2 techniques·derived
Ransomware deployed against gaming targets for personal profit. Virtual currency manipulation and COVID-19 relief fund theft.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Multiple software vendors trojanised to reach downstream customers
Rapid weaponisation — Citrix, Cisco, Zoho, and Log4Shell exploited within days of disclosure
sethc.exe and utilman.exe replacement for pre-authentication access
Stolen certificates from gaming companies
Winnti kernel driver
Signed legitimate executables used to load malicious DLLs
Ransomware deployed against gaming targets for personal profit
Virtual currency manipulation and COVID-19 relief fund theft
Compromise of at least six U.S. state government networks via a USAHERDS zero-day and Log4Shell exploitation within days of disclosure, demonstrating unusually fast weaponisation of new vulnerabilities.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both MSS-linked contractor operations; overlapping use of ShadowPad and shared certificate abuse patterns.
Overlapping implant families consistent with a shared PRC contractor supply chain.
Both MSS-aligned contractor operations with distinct regional taskings.
Curated links to the reports that established what is known about this group.