APT41
Chinese state-sponsored with simultaneous criminal mandate (MSS-affiliated) · Dual mandate: state-directed espionage against strategic industries (for Beijing) and independent financial cybercrime
Tactics, Techniques & Procedures (TTPs)
- Dual-track operations: government espionage during Chinese business hours, financial cybercrime outside those hours, from the same group and infrastructure
- Supply chain compromise for mass distribution (2017 NetSarang SHADOWPAD — infected 100,000+ organisations via legitimate software update)
- SHADOWPAD modular backdoor: the premier long-duration persistence tool, successor to PlugX, across the APT41 toolkit
- HIGHNOON (custom-compiled Cobalt Strike BEACON variant): evades BEACON signatures while retaining full C2 capability
- Rapid CVE weaponisation: exploitation of critical vulnerabilities within hours of public disclosure (CVE-2020-10189 documented)
- 2026 ELF Linux backdoor with zero VirusTotal detections: C2 via SMTP port 25, cloud credential exfiltration from AWS, Azure, GCP, and Alibaba Cloud
- Virtual currency theft from online gaming platforms (financial mandate): in-game currency and item theft for resale
Known Targets
Analyst Notes
APT41 is unique among Chinese APTs for its explicit dual mandate: MSS-directed espionage alongside financially motivated cybercrime (gaming currency theft, supply chain attacks, ransomware-adjacent operations). Five Chinese nationals were DoJ-indicted in September 2020; operations continued without material reduction. The 2017 NetSarang SHADOWPAD supply chain compromise infected 100,000+ organisations via a legitimate software update — predating the SolarWinds campaign by three years. The 2026 Linux backdoor (zero VirusTotal detections, SMTP port 25 C2) demonstrates continued investment in novel capability. Active across more sectors and geographies than any other single Chinese APT cluster.
Also Known As