APT41__2019__report_APT41.pdf
ID: 07dfc89c-ceb2-4c4a-a6ce-bd6be0252731
STIX ID: report--07dfc89c-ceb2-4c4a-a6ce-bd6be0252731
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-08-01
Last Modified Date: 2019-08-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye assesses with high confidence that APT41 is a prolific China-linked threat actor that conducts dual espionage and financially-motivated operations. The report documents targeting across healthcare, high-tech, telecoms, video games and other sectors, detailed case studies (e.g., game industry and healthcare), multiple supply-chain compromises (including NetSarang and the ASUS "ShadowHammer" incident), extensive malware families (POISONPLUG, HIGHNOON, CRACKSHOT, ROCKBOOT, etc.), abuse of legitimate code-signing certificates, operational timelines, TTP mappings, and a long list of IOCs for detection and response.
