Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape
🦠

APT41

Aliases

Amoeba, BARIUM, BRONZE ATLAS, BRONZE EXPORT, Blackfly, Brass Typhoon, Earth Baku, G0044, G0096, Grayfly, HOODOO, LEAD, Red Kelpie, TA415, WICKED PANDA, WICKED SPIDER

Tags
State-SponsoredData Exfil.
Attribution
🇨🇳
Incidents
Earth Baku campaignCyberoam breach (2018)China-Linked Actors Target U.S. Policy-Oriented Non-Profit Organisations
References
https://attack.mitre.org/groups/G0096/
Last edited
Oct 14, 2024 1:44 PM
Status
Stub
Cloud-fluent
Targeted industries
TelecommunicationHigh-techHealthcare/Medical

APT41 is a sophisticated cyber threat group believed to conduct both state-sponsored espionage and financially motivated cybercrime. The group's operations have been linked to the Chinese government and are characterized by a dual mission strategy, targeting a wide range of sectors including healthcare, telecommunications, and high-tech industries. APT41 employs a variety of advanced techniques, including supply chain compromises, exploitations of software vulnerabilities, and the use of custom malware. Their ability to pivot between espionage and financial gain highlights a unique operational model in the realm of cyber threats.

Made with 💙 by Wiz

Last Updated: April 3, 2025