logo

APT41__2019__Fireeye_rpt-apt41_08-07-2019.pdf

ID: 84774e66-e1dd-4c6b-947b-b2205bbba676

STIX ID: report--84774e66-e1dd-4c6b-947b-b2205bbba676

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-09-04

Last Modified Date: 2019-09-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report profiles APT41 as a sophisticated China-linked actor that simultaneously conducts state-backed espionage (targeting healthcare, high-tech, telecoms, media, and government-related targets) and financially motivated operations (notably against the video-game industry). The analysis documents supply-chain compromises (e.g., NetSarang, ASUS ShadowHammer), abuse of legitimate code-signing certificates, use of advanced persistence (bootkits/rootkits), a broad malware toolkit (POISONPLUG, HIGHNOON, CROSSWALK, CRACKSHOT, etc.), extensive IOCs (hashes, domains, email addresses, Google Docs URLs), timelines, and attribution indicators supporting a high-risk, wide-impact adversary.