APT41 is a prolific China-aligned espionage and cybercrime threat actor widely associated with the broader Winnti ecosystem. Common aliases include Winnti, Barium, Double Dragon, Wicked Panda, Wicked Spider, Brass Typhoon, Bronze Atlas, Blackfly, Grayfly, Red Kelpie, Red Typhoon, Aquatic Panda, Earth Baku, and in some reporting Earth Lusca or related Winnti-umbrella clusters. Public reporting and U.S. indictments have linked members of the group to work on behalf of the Ministry of State Security while also conducting financially motivated operations, making APT41 notable for blending state-directed espionage with profit-seeking intrusion activity. APT41 has targeted a broad range of sectors globally, including government, healthcare, telecommunications, technology, software and video game companies, and critical infrastructure. Victimology has included government systems and service providers, telecom operators, healthcare organizations, and strategic infrastructure environments. Reporting has also associated APT41-linked or overlapping activity with targeting in Africa and with infrastructure overlap in operations against Indian critical infrastructure, although some of those campaigns were tracked separately rather than conclusively attributed to APT41 itself. Operationally, APT41 is known for versatile post-compromise tradecraft across discovery, persistence, credential access, lateral movement, defense evasion, and data theft. Documented behaviors include system and network enumeration using native commands, registry querying to identify host and network configuration details, discovery of installed security products and endpoint defenses, registry modification for persistence, and creation or modification of startup mechanisms. The group has also been associated with process injection and use of common intrusion tooling such as Cobalt Strike. ATT&CK-mapped reporting frequently highlights strong use of discovery, credential access, masquerading, indicator removal, and command-and-scripting techniques, with overlap in tradecraft relative to other Chinese state-linked actors. APT41 is especially notable for software supply-chain compromise and trusted-relationship abuse. It has been described as pioneering large-scale supply-chain intrusions by trojanizing shared software components and leveraging access to developer or enterprise environments to reach downstream victims. The group is also associated with advanced stealth capabilities within the Winnti umbrella, including malware and implants linked in public reporting to firmware- and rootkit-level persistence, though such tooling may not be exclusive to APT41 alone. The actor sits within a complex cluster of overlapping aliases, subgroups, and contractor-linked teams in the Chinese intrusion ecosystem. Some names used in public reporting may refer to partially overlapping activity rather than a perfectly identical set of operators, so the broader Winnti umbrella remains important context when interpreting APT41-related attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
53 malware families attributed to this actor across reporting.
48 additional families tracked in Mallory.
53 CVEs this actor has used in observed campaigns. 53 of them exploited in the wild.
APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.
APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.
Infection sequences start with the exploitation of known security flaws in public-facing ... Microsoft Exchange Server (ProxyShell) ... servers to drop web shells and deliver Cobalt Strike for lateral movement.
During C0017, APT41 exploited ... CVE-2021-44228 in Log4j... During C0018, the threat actors exploited ... several Log4Shell vulnerabilities, including CVE-2021-44228... Magic Hound has exploited the Log4j utility (CVE-2021-44228).
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
48 more CVEs tied to this actor tracked in Mallory.
557 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a priority ATT&CK group for government and telecommunications threat modeling.
Referenced as a known threat group whose TTPs were emulated by AI agents in a study assessing whether TTP-based attribution can be undermined.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.