Threat group.View on attack.mitre.org
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1003.002 Security Account Manager |
APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.003 NTDS |
APT41 used ntdsutil to obtain a copy of the victim environment |
| T1005 Data from Local System |
APT41 has uploaded files and data from a compromised host. |
| T1008 Fallback Channels |
APT41 used the Steam community page as a fallback mechanism for C2. |
| T1012 Query Registry |
APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| T1014 Rootkit |
APT41 deployed rootkits on Linux systems. |
| T1016 System Network Configuration Discovery |
APT41 collected MAC addresses from victim machines. |
| T1018 Remote System Discovery |
APT41 has used MiPing to discover active systems in the victim network. |
| T1021.001 Remote Desktop Protocol |
APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet. |
| T1021.002 SMB/Windows Admin Shares |
APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| T1027 Obfuscated Files or Information |
APT41 used VMProtected binaries in multiple intrusions. |
| T1027.002 Software Packing |
APT41 uses packers such as Themida to obfuscate malicious files. |
| T1030 Data Transfer Size Limits |
APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection. |
| T1033 System Owner/User Discovery |
APT41 has executed |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.