GAME OVER: Detecting and Stopping an APT41 Operation
ID: c16a6cf8-737d-462d-8385-14278e2a414b
STIX ID: report--c16a6cf8-737d-462d-8385-14278e2a414b
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-09-18
Last Modified Date: 2019-09-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes an APT41 operation that exploited CVE-2019-3396 in Confluence to run arbitrary commands and deploy a China Chopper webshell, the HIGHNOON backdoor, and ACEHASH credential-stealing components; network and endpoint telemetry allowed rapid detection and containment before broader compromise. The report provides exploit payloads, decoded HIGHNOON commands, file and IP indicators, and recommended defensive takeaways including patching, combined endpoint/network visibility, and full incident scoping.
