APT41
MISPNation-state
CN
Unknown
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.(Citation: apt41_mandiant) Notable behaviors include using a wide range of malware and tools to complete mission objectives. [APT41](https://attack.mitre.org/groups/G0096) overlaps at least partially with public reporting on groups including BARIUM and [Winnti Group](https://attack.mitre.org/groups/G0044).(Citation: FireEye APT41 Aug 2019)(Citation: Group IB APT 41 June 2021)
Tecniche Utilizzate (82)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1003.002 | Security Account Manager | - |
| T1003.003 | NTDS | - |
| T1005 | Data from Local System | - |
| T1008 | Fallback Channels | - |
| T1012 | Query Registry | - |
| T1014 | Rootkit | - |
| T1016 | System Network Configuration Discovery | - |
| T1018 | Remote System Discovery | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1021.002 | SMB/Windows Admin Shares | - |
| T1027 | Obfuscated Files or Information | - |
| T1027.002 | Software Packing | - |
| T1030 | Data Transfer Size Limits | - |
| T1033 | System Owner/User Discovery | - |
Riferimenti (10)
- securelist.com - 57585
- securelist.com - 37029
- williamshowalter.com - A Universal Windows Bootkit
- microsoft.com - Detecting Threat Actors In Recent German Industrial Attacks With Windows Defender Atp
- securelist.com - 70991
- medium.com - Winnti More Than Just Windows And Gates E4f03436031a
- dw.com - A 36695341
- bleepingcomputer.com - Teamviewer Confirms Undisclosed Breach From 2016
- blog.trendmicro.com - Winnti Abuses Github
- dw.com - A 48196004
Alias (2372)
Malware Utilizzato (32)
Metadata
| ID: | 260 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |