APT41 is a prolific China-nexus espionage and cyber intrusion group widely associated with the broader Winnti ecosystem and tracked under numerous aliases including Barium, Winnti, Double Dragon, Wicked Panda, Wicked Spider, Brass Typhoon, Bronze Atlas, Blackfly, Grayfly, Red Kelpie, Red Diablo, and in some reporting Earth Lusca-related naming. The group has been linked to activity aligned with the interests of the People’s Republic of China and has been publicly associated with contractors working on behalf of the Ministry of State Security. It is notable for combining traditional state-directed espionage with financially motivated operations in some periods, as well as for extensive tool sharing and overlap with other China-aligned clusters. APT41 has targeted a broad range of sectors globally, including government, healthcare, telecommunications, education, software and technology providers, and critical infrastructure. Reported victimology spans North America, Europe, and Asia, with repeated focus on government networks, telecom environments, higher education, healthcare organizations, and strategic service providers. The group has also been associated with activity affecting supply chains and trusted software ecosystems, making it one of the more operationally versatile Chinese intrusion sets. Tradecraft attributed to APT41 includes exploitation of public-facing applications, supply-chain compromise, DLL side-loading, use of signed binaries for proxy execution, extensive hands-on-keyboard post-compromise activity, and deployment of modular malware and loaders. The group is frequently associated with the Winnti malware lineage and with use of ShadowPad, Cobalt Strike, and other shared Chinese intrusion tooling. Reporting has also linked APT41 to advanced persistence mechanisms ranging from Windows autostart and service-related registry changes to highly sophisticated firmware-level compromise, including the MoonBounce UEFI implant. Observed post-compromise behavior includes system and network discovery using native commands, registry querying to identify configuration details such as remote access and network settings, security software discovery to identify defensive products, credential access, lateral movement, and defense evasion. ATT&CK techniques repeatedly associated with the group include Command and Scripting Interpreter, Security Software Discovery, System Information Discovery, Registry discovery and modification, Process Injection, Masquerading, Indicator Removal on Host, Obtain Capabilities, and OS Credential Dumping. APT41 is also regularly described as relying on modular and reusable tooling rather than exclusively bespoke malware, contributing to overlap with other Chinese threat clusters and complicating attribution. APT41 sits near the center of many comparative analyses of Chinese intrusion activity because its documented TTP set overlaps substantially with other China-aligned actors such as Volt Typhoon, Mustang Panda, and Stone Panda. That centrality reflects both the breadth of its operations and the degree of shared tooling and methodology across the Chinese state-sponsored ecosystem. Despite this overlap, APT41 remains one of the most recognized and extensively tracked Chinese advanced persistent threat groups due to its scale, operational maturity, and history of high-impact espionage and supply-chain operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
53 malware families attributed to this actor across reporting.
48 additional families tracked in Mallory.
53 CVEs this actor has used in observed campaigns. 53 of them exploited in the wild.
APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.
APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.
Infection sequences start with the exploitation of known security flaws in public-facing ... Microsoft Exchange Server (ProxyShell) ... servers to drop web shells and deliver Cobalt Strike for lateral movement.
During C0017, APT41 exploited ... CVE-2021-44228 in Log4j... During C0018, the threat actors exploited ... several Log4Shell vulnerabilities, including CVE-2021-44228... Magic Hound has exploited the Log4j utility (CVE-2021-44228).
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
48 more CVEs tied to this actor tracked in Mallory.
557 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for TTP overlap with similar Chinese-origin post-exploitation tooling targeting government and education sectors.
Referenced as a priority ATT&CK group for government and telecommunications threat modeling.
Referenced as a known threat group whose TTPs were emulated by AI agents in a study assessing whether TTP-based attribution can be undermined.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.