Skip to content
← All Threat Actors
Nation-State critical China (PRC)

APT41

Chinese state-sponsored with simultaneous criminal mandate (MSS-affiliated) · Dual mandate: state-directed espionage against strategic industries (for Beijing) and independent financial cybercrime

Reports 1
Active Since 2012
Last Reported 10 Jun 2026
Sectors Targeted healthcare, finance, communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Dual-track operations: government espionage during Chinese business hours, financial cybercrime outside those hours, from the same group and infrastructure
  • Supply chain compromise for mass distribution (2017 NetSarang SHADOWPAD — infected 100,000+ organisations via legitimate software update)
  • SHADOWPAD modular backdoor: the premier long-duration persistence tool, successor to PlugX, across the APT41 toolkit
  • HIGHNOON (custom-compiled Cobalt Strike BEACON variant): evades BEACON signatures while retaining full C2 capability
  • Rapid CVE weaponisation: exploitation of critical vulnerabilities within hours of public disclosure (CVE-2020-10189 documented)
  • 2026 ELF Linux backdoor with zero VirusTotal detections: C2 via SMTP port 25, cloud credential exfiltration from AWS, Azure, GCP, and Alibaba Cloud
  • Virtual currency theft from online gaming platforms (financial mandate): in-game currency and item theft for resale

Known Targets

Healthcare and pharmaceutical organisations (COVID vaccine research, drug development IP)Telecommunications operators across Southeast Asia, North America, and EuropeTechnology companies (gaming, enterprise software)Government agencies across 40+ countries and 15+ sectorsFinancial services and cryptocurrency exchangesDefence contractors and supply chain organisations

Analyst Notes

APT41 is unique among Chinese APTs for its explicit dual mandate: MSS-directed espionage alongside financially motivated cybercrime (gaming currency theft, supply chain attacks, ransomware-adjacent operations). Five Chinese nationals were DoJ-indicted in September 2020; operations continued without material reduction. The 2017 NetSarang SHADOWPAD supply chain compromise infected 100,000+ organisations via a legitimate software update — predating the SolarWinds campaign by three years. The 2026 Linux backdoor (zero VirusTotal detections, SMTP port 25 C2) demonstrates continued investment in novel capability. Active across more sectors and geographies than any other single Chinese APT cluster.

Also Known As

Winnti Group (Kaspersky/ESET)Double Dragon (Mandiant)BARIUM (Microsoft legacy)Brass Typhoon (Microsoft current)Bronze Atlas (Secureworks)G0096 (MITRE)