APT41__2021__Operation_Harvest_A_Deep_Dive_into_a_Long-term_Campaign_McAfee_Blogs.pdf
ID: 0dc4f2e2-6a88-48c4-8b89-c61ef93c08ff
STIX ID: report--0dc4f2e2-6a88-48c4-8b89-c61ef93c08ff
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-09-15
Last Modified Date: 2021-09-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation "Harvest" is a McAfee ATR investigation into a multi-year targeted intrusion that established persistent access to victim networks to steal intellectual property and sensitive intelligence. The adversary compromised web-facing servers to stage tools, deployed PlugX and Winnti variants (including DLL sideloading and custom backdoors), used credential-dumping and privilege-escalation tools for lateral movement, and exfiltrated data via staged web servers, C2 channels and DNS tunneling; the report maps these actions to MITRE ATT&CK, provides IOCs, and notes strong overlap with known APT activity consistent with a Chinese-aligned actor.
