logo

APT41__2021__Operation_Harvest_A_Deep_Dive_into_a_Long-term_Campaign_McAfee_Blogs.pdf

ID: 0dc4f2e2-6a88-48c4-8b89-c61ef93c08ff

STIX ID: report--0dc4f2e2-6a88-48c4-8b89-c61ef93c08ff

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-09-15

Last Modified Date: 2021-09-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation "Harvest" is a McAfee ATR investigation into a multi-year targeted intrusion that established persistent access to victim networks to steal intellectual property and sensitive intelligence. The adversary compromised web-facing servers to stage tools, deployed PlugX and Winnti variants (including DLL sideloading and custom backdoors), used credential-dumping and privilege-escalation tools for lateral movement, and exfiltrated data via staged web servers, C2 channels and DNS tunneling; the report maps these actions to MITRE ATT&CK, provides IOCs, and notes strong overlap with known APT activity consistent with a Chinese-aligned actor.