APT41

G0096

Threat group.View on attack.mitre.org

About this group

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

Techniques used82

Procedure examples82

TechniqueProcedure example
T1003.001
LSASS Memory

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

T1003.002
Security Account Manager

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.003
NTDS

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1005
Data from Local System

APT41 has uploaded files and data from a compromised host.

T1008
Fallback Channels

APT41 used the Steam community page as a fallback mechanism for C2.

T1012
Query Registry

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

T1014
Rootkit

APT41 deployed rootkits on Linux systems.

T1016
System Network Configuration Discovery

APT41 collected MAC addresses from victim machines.

T1018
Remote System Discovery

APT41 has used MiPing to discover active systems in the victim network.

T1021.001
Remote Desktop Protocol

APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet.

T1021.002
SMB/Windows Admin Shares

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

T1027
Obfuscated Files or Information

APT41 used VMProtected binaries in multiple intrusions.

T1027.002
Software Packing

APT41 uses packers such as Themida to obfuscate malicious files.

T1030
Data Transfer Size Limits

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

T1033
System Owner/User Discovery

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

View all 82 procedure examples

Software32

Show 8 more

Campaigns2

References3

  1. FireEye APT41 Aug 2019 Open source
    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
  2. Group IB APT 41 June 2021 Open source
    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.
  3. apt41_mandiant Open source
    Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.