logo

APT41: A Dual Espionage and Cyber Crime Operation

ID: c17b9cbb-f7a6-4ef7-90bf-191bb1e41d8f

STIX ID: report--c17b9cbb-f7a6-4ef7-90bf-191bb1e41d8f

Threat Score

92/100

Uploaded: 2026-08-14

Published Date: 2019-09-18

Last Modified Date: 2019-09-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report documents APT41, a prolific China-based threat actor that simultaneously conducts state-sponsored espionage and financially motivated operations since at least 2012. The group targets industries including healthcare, telecommunications, high-tech, education and video games, and is notable for supply-chain compromises, theft of digital certificates, deployment of a large and diverse malware toolkit (including bootkits, backdoors, credential stealers and attempted ransomware), rapid lateral movement across Windows and Linux systems, and operational behaviors suggesting both contractor-style for-profit activity and sophisticated espionage tradecraft.