logo

GAME OVER: Detecting and Stopping an APT41 Operation

ID: c16a6cf8-737d-462d-8385-14278e2a414b

STIX ID: report--c16a6cf8-737d-462d-8385-14278e2a414b

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-09-18

Last Modified Date: 2019-09-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes an APT41 operation that exploited CVE-2019-3396 in Confluence to run arbitrary commands and deploy a China Chopper webshell, the HIGHNOON backdoor, and ACEHASH credential-stealing components; network and endpoint telemetry allowed rapid detection and containment before broader compromise. The report provides exploit payloads, decoded HIGHNOON commands, file and IP indicators, and recommended defensive takeaways including patching, combined endpoint/network visibility, and full incident scoping.