Cyber overview
Cyber threat actor

Brass Typhoon

PRC state-sponsored (umbrella designator) · active since Pre-2019

Microsoft umbrella designation for clusters using ShadowPad, frequently overlapping with APT41 tradecraft against telecom and government.

Aliases
BARIUM (legacy)ShadowPad cluster
Primary targets
Telecom Government IT service providers

MITRE ATT&CK techniques

3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

TacticTechniqueProcedureTargetsCitation
Initial AccessT1190
Exploit Public-Facing Application
Public-facing exploits across telecom and IT service providers (umbrella cluster overlapping APT41).
-Microsoft threat actor naming
PersistenceT1554
ShadowPad modular backdoor
ShadowPad implant with rotating plug-ins shared across MSS contractor clusters.
-Microsoft threat actor naming
Defense EvasionT1574.002
DLL Side-Loading
Legitimate signed binaries side-load ShadowPad loaders to bypass application allow-listing.
-Microsoft threat actor naming