logo

APT41__2020__This_Is_Not_a_Test_APT41_Initiates_Global_Intrusion_Campaign_Using_Multiple_Exploits_FireEye_Inc.pdf

ID: 4d323de8-6bfd-43d8-a433-082375afa89f

STIX ID: report--4d323de8-6bfd-43d8-a433-082375afa89f

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-03-26

Last Modified Date: 2020-03-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye documents a widespread 2020 APT41 intrusion campaign that leveraged multiple public exploits (notably Citrix CVE-2019-19781 and Zoho ManageEngine CVE-2020-10189 plus Cisco router flaws) to compromise organizations across many countries and industries, deploying Cobalt Strike BEACON, Meterpreter, and other tools; the report provides timelines, example exploit traffic, IOCs (IPs, domain, filenames, MD5s), detection signatures, ATT&CK mappings, and YARA rules for detection and hunting.