G0096 · 85 ATT&CK techniques · 17 correlated reports

APT41

Aliases: Wicked Panda, Brass Typhoon, BARIUM

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

Open interactive actor investigation

ATT&CK techniques

T1078
Valid Accounts
T1082
System Information Discovery
T1195.002
Compromise Software Supply Chain
T1069
Permission Groups Discovery
T1562.006
Indicator Blocking
T1595.003
Wordlist Scanning
T1059.001
PowerShell
T1014
Rootkit
T1087.002
Domain Account
T1555.003
Credentials from Web Browsers
T1036.005
Match Legitimate Name or Location
T1543.003
Windows Service
T1071.002
File Transfer Protocols
T1018
Remote System Discovery
T1027.002
Software Packing
T1553.002
Code Signing
T1596.005
Scan Databases
T1588.002
Tool
T1098.007
Additional Local or Domain Groups
T1021.002
SMB/Windows Admin Shares
T1037
Boot or Logon Initialization Scripts
T1136.001
Local Account
T1542.003
Bootkit
T1087.001
Local Account
T1071.001
Web Protocols
T1070.001
Clear Windows Event Logs
T1135
Network Share Discovery
T1599
Network Boundary Bridging
T1480.001
Environmental Keying
T1484.001
Group Policy Modification
T1595.002
Vulnerability Scanning
T1005
Data from Local System
T1133
External Remote Services
T1070.004
File Deletion
T1566.001
Spearphishing Attachment
T1053.005
Scheduled Task
T1547.001
Registry Run Keys / Startup Folder
T1546.008
Accessibility Features
T1110
Brute Force
T1550.002
Pass the Hash
T1574.006
Dynamic Linker Hijacking
T1059.003
Windows Command Shell
T1003.002
Security Account Manager
T1568.002
Domain Generation Algorithms
T1569.002
Service Execution
T1071.004
DNS
T1046
Network Service Discovery
T1560.001
Archive via Utility
T1218.011
Rundll32
T1102.001
Dead Drop Resolver
T1008
Fallback Channels
T1555
Credentials from Password Stores
T1496.001
Compute Hijacking
T1003.003
NTDS
T1049
System Network Connections Discovery
T1059.004
Unix Shell
T1486
Data Encrypted for Impact
T1574.002
DLL Side-Loading
T1016
System Network Configuration Discovery
T1033
System Owner/User Discovery
T1105
Ingress Tool Transfer
T1203
Exploitation for Client Execution
T1218.001
Compiled HTML File
T1112
Modify Registry
T1090
Proxy
T1003.001
LSASS Memory
T1213.003
Code Repositories
T1197
BITS Jobs
T1012
Query Registry
T1083
File and Directory Discovery
T1656
Impersonation
T1055
Process Injection
T1021.001
Remote Desktop Protocol
T1190
Exploit Public-Facing Application
T1570
Lateral Tool Transfer
T1027
Obfuscated Files or Information
T1104
Multi-Stage Channels
T1030
Data Transfer Size Limits
T1047
Windows Management Instrumentation
T1056.001
Keylogging
T1070.003
Clear Command History
T1036.004
Masquerade Task or Service
T1574.001
DLL Search Order Hijacking
T1589.001
Credentials
T1589.003
Employee Names

Correlated CTI and IR reports

APT41 / Operation DragonRx
CTI Analyst Field Manual · explicit report mention
APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise
1200km CTI repository · explicit report mention
Attack Playbook — Operation DragonRx
1200km CTI repository · explicit report mention
Attribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution
1200km CTI repository · explicit report mention
DFIR Playbook — Operation DragonRx
1200km CTI repository · explicit report mention
Detection Guide — Operation DragonRx
1200km CTI repository · explicit report mention
From Threat Intelligence to Detection: A Practitioner's Guide
1200km CTI repository · explicit report mention
Lab Architecture — Operation DragonRx
1200km CTI repository · explicit report mention
Malicious Activity as a Statistical Signal: A Detection Engineering Analysis of Anomaly-Based Detection
1200km CTI repository · explicit report mention
Operation DragonRx — APT41 Full Attack Simulation
1200km CTI repository · explicit report mention
Operation DragonRx — APT41 Full Attack Simulation
1200km CTI repository · explicit report mention
Operation DragonRx: Simulating an APT41 Attack End-to-End — From Log4Shell to DFIR and Malware Analysis
1200km CTI repository · explicit report mention
RxPhage — Custom PlugX-lite Implant
1200km CTI repository · explicit report mention
APT41 Targeting Pharmaceutical Sector Log4Shell to Domain Compromise
1200km Medium · authored report mention
Attack Playbook Operation DragonRx
1200km Medium · authored report mention
From Threat Intelligence to Detection A Practitioner s Guide
1200km Medium · authored report mention
Operation DragonRx Simulating an APT41 Attack End to End From Log4Shell to DFIR and Malware
1200km Medium · authored report mention

Continue the investigation