FORENSIA

THREAT_ACTOR · G0096

APT41

Also known as: APT41, Wicked Panda, Brass Typhoon, BARIUM

Profile

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

MITRE ATT&CK ↗

Techniques

82 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1003.003 NTDST1005 Data from Local SystemT1008 Fallback ChannelsT1012 Query RegistryT1014 RootkitT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1027 Obfuscated Files or InformationT1027.002 Software PackingT1030 Data Transfer Size LimitsT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1037 Boot or Logon Initialization ScriptsT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1055 Process InjectionT1056.001 KeyloggingT1059.001 PowerShellT1059.003 Windows Command ShellT1059.004 Unix ShellT1069 Permission Groups DiscoveryT1070.003 Clear Command HistoryT1070.004 File DeletionT1071.001 Web ProtocolsT1071.002 File Transfer ProtocolsT1071.004 DNST1078 Valid AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1090 ProxyT1098.007 Additional Local or Domain GroupsT1102.001 Dead Drop ResolverT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1110 Brute ForceT1112 Modify RegistryT1133 External Remote ServicesT1135 Network Share DiscoveryT1136.001 Local AccountT1190 Exploit Public-Facing ApplicationT1195.002 Compromise Software Supply ChainT1197 BITS JobsT1203 Exploitation for Client ExecutionT1213.003 Code RepositoriesT1218.001 Compiled HTML FileT1218.011 Rundll32T1480.001 Environmental KeyingT1484.001 Group Policy ModificationT1486 Data Encrypted for ImpactT1496.001 Compute HijackingT1542.003 BootkitT1543.003 Windows ServiceT1546.008 Accessibility FeaturesT1547.001 Registry Run Keys / Startup FolderT1550.002 Pass the HashT1553.002 Code SigningT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1568.002 Domain Generation AlgorithmsT1569.002 Service ExecutionT1570 Lateral Tool TransferT1574.001 DLLT1574.006 Dynamic Linker HijackingT1588.002 ToolT1595.002 Vulnerability ScanningT1595.003 Wordlist ScanningT1596.005 Scan DatabasesT1599 Network Boundary BridgingT1684.001 ImpersonationT1685 Disable or Modify ToolsT1685.005 Clear Windows Event Logs

Software

32 malware/tools attributed to this actor.

MimikatzpwdumpPlugXChina ChopperDerusbigh0st RATNetBLACKCOFFEEASPXSpyftpPingipconfignetstatdsqueryROCKBOOTCobalt StrikecertutilBITSAdminPowerSploitsqlmapImpacketEmpirenjRATZxShellWinnti for LinuxMESSAGETAPShadowPadKEYPLUGDUSTPANDUSTTRAPLightSpyMOPSLED

Related corpus activity

10,334 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT41.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,334.