82
Techniques
32
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.

View MITRE record ↗

Techniques by Tactic (82)
Resource Development
Toolsets (32)
🐛
ASPXSpy S0073
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Linux, macOS, Windows
🐛
DUSTPAN S1158
Malware · Windows
🐛
DUSTTRAP S1159
Malware · Windows
🐛
Derusbi S0021
Malware · Windows, Linux
🐛
KEYPLUG S1051
Malware · Linux, Windows
🐛
LightSpy S1185
Malware · Android, Windows, iOS, macOS
🐛
Malware · Linux
🐛
MOPSLED S1221
Malware · Linux
🐛
PlugX S0013
Malware · Windows
🐛
ROCKBOOT S0112
Malware · Windows
🐛
ShadowPad S0596
Malware · Windows
🐛
Malware · Linux
🐛
ZxShell S0412
Malware · Windows
🐛
gh0st RAT S0032
Malware · Windows, macOS
🐛
njRAT S0385
Malware · Windows
🔧
BITSAdmin S0190
Tool · Windows
🔧
Empire S0363
Tool · Linux, macOS, Windows
🔧
Impacket S0357
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Net S0039
Tool · Windows
🔧
Ping S0097
Tool
🔧
Tool · Windows
🔧
certutil S0160
Tool · Windows
🔧
dsquery S0105
Tool · Windows
🔧
ftp S0095
Tool · Linux, Windows, macOS
🔧
ipconfig S0100
Tool
🔧
netstat S0104
Tool
🔧
pwdump S0006
Tool · Windows
🔧
sqlmap S0225
Tool
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-8625View full details on NVD
↑