logo

APT41 Targeting U.S. State Government Networks

ID: 7c2d0388-2ab0-4738-9159-a8720ab3e546

STIX ID: report--7c2d0388-2ab0-4738-9159-a8720ab3e546

Threat Score

92/100

Uploaded: 2026-05-25

Created by: JurassiHack

TLP:CLEAR
...
...
Mandiant reports that APT41 conducted a months-long campaign (May 2021–Feb 2022) against U.S. state government networks by exploiting internet-facing ASP.NET web applications (notably a USAHerds zero-day and Log4j), deploying multiple malware families (KEYPLUG, DEADEYE, DUSTPAN), performing credential harvesting and Active Directory reconnaissance, and exfiltrating PII; the report includes detailed TTPs, IOCs (hashes, IPs, domains), and hunting/YARA rules.