Cyber overview
Cyber threat actor

APT41

MSS contractor (Chengdu 404) · active since 2012

Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.

Aliases
Double DragonWicked PandaBARIUMWinnti
Primary targets
Healthcare Telecom Game studios Government Higher education

MITRE ATT&CK techniques

4 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

TacticTechniqueProcedureTargetsCitation
Initial AccessT1195.002
Supply Chain Compromise: Software
Trojanized legitimate software updates (CCleaner, ASUS Live Update, NetSarang) to seed victims globally.
Downstream enterprise usersMandiant APT41 report
PersistenceT1554
Implant Container (Winnti/ShadowPad)
Winnti and ShadowPad modular backdoors with plug-ins for credential theft and lateral movement.
-Mandiant APT41 report
Lateral MovementT1021.001
Remote Services: RDP / Cobalt Strike
Cobalt Strike beacons, custom loaders, and RDP with stolen creds across victim estates.
-DOJ indictment
ImpactT1496
Resource Hijacking (cryptocurrency)
Financially motivated side ops: cryptocurrency theft and game studio in-game currency manipulation.
Game studios, crypto firmsMandiant APT41 report

Curated incidents

  1. 2020-09-16·Cross-sector·Global
    DOJ indicts 5 APT41 members in Chengdu 404

    Charges cover 100+ victim companies including game studios and government targets.