Cyber threat actor
APT41
MSS contractor (Chengdu 404) · active since 2012
Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.
Aliases
Double DragonWicked PandaBARIUMWinnti
Primary targets
Healthcare Telecom Game studios Government Higher education
MITRE ATT&CK techniques
4 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1195.002 Supply Chain Compromise: Software | Trojanized legitimate software updates (CCleaner, ASUS Live Update, NetSarang) to seed victims globally. | Downstream enterprise users | Mandiant APT41 report |
| Persistence | T1554 Implant Container (Winnti/ShadowPad) | Winnti and ShadowPad modular backdoors with plug-ins for credential theft and lateral movement. | - | Mandiant APT41 report |
| Lateral Movement | T1021.001 Remote Services: RDP / Cobalt Strike | Cobalt Strike beacons, custom loaders, and RDP with stolen creds across victim estates. | - | DOJ indictment |
| Impact | T1496 Resource Hijacking (cryptocurrency) | Financially motivated side ops: cryptocurrency theft and game studio in-game currency manipulation. | Game studios, crypto firms | Mandiant APT41 report |
Curated incidents
- 2020-09-16·Cross-sector·GlobalDOJ indicts 5 APT41 members in Chengdu 404
Charges cover 100+ victim companies including game studios and government targets.