APT41__2019__Fireeye_rpt-apt41_08-07-2019.pdf
ID: 84774e66-e1dd-4c6b-947b-b2205bbba676
STIX ID: report--84774e66-e1dd-4c6b-947b-b2205bbba676
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-09-04
Last Modified Date: 2019-09-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report profiles APT41 as a sophisticated China-linked actor that simultaneously conducts state-backed espionage (targeting healthcare, high-tech, telecoms, media, and government-related targets) and financially motivated operations (notably against the video-game industry). The analysis documents supply-chain compromises (e.g., NetSarang, ASUS ShadowHammer), abuse of legitimate code-signing certificates, use of advanced persistence (bootkits/rootkits), a broad malware toolkit (POISONPLUG, HIGHNOON, CROSSWALK, CRACKSHOT, etc.), extensive IOCs (hashes, domains, email addresses, Google Docs URLs), timelines, and attribution indicators supporting a high-risk, wide-impact adversary.
