APT41 is a Chinese state-sponsored threat actor that conducts espionage aligned with Beijing's interests alongside financially motivated cybercrime. It is also known as Brass Typhoon, Wicked Panda, Barium, and Double Dragon. APT41 is frequently associated with the Winnti name, although the broader Winnti umbrella encompasses multiple Chinese threat groups with overlapping tools and activities rather than a single interchangeable identity. Its targets include government agencies, gaming and gambling organizations, software production environments, and online billing and payment services. APT41 exploited a zero-day vulnerability in the USAHERDS application to attack multiple U.S. state governments during 2021. Its financially motivated operations have included ransomware deployment, cryptojacking, and theft of video-game currency. Initial-access methods include spearphishing with compiled HTML attachments, exploitation of public-facing applications, software supply-chain compromise, and access through third-party VPN connections. Documented exploitation includes CVE-2020-10189 in Zoho ManageEngine Desktop Central and CVE-2019-19781 in Citrix appliances. The group has inserted malicious code into legitimate signed software distributed to end users. APT41 steals credentials through memory-based password-hash dumping and DCSync, using tools including Mimikatz and Windows Credential Editor. It uses compromised accounts and RDP for lateral movement, and establishes persistence through modified Windows services, scheduled tasks, and newly created accounts. Its toolkit includes Cobalt Strike and custom malware such as TIDYELF and WINTERLOVE. Defense-evasion methods include DLL hijacking, process injection, VMProtect-protected binaries, and abuse of legitimate administration utilities. The group profiles compromised systems, adapts to defensive activity, and stages targeted files in archives for exfiltration. It has also deployed Encryptor RaaS to encrypt victim files and demand ransom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
70 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
62 malware families attributed to this actor across reporting.
57 additional families tracked in Mallory.
42 CVEs this actor has used in observed campaigns. 42 of them exploited in the wild.
APT29 has exploited CVE-2019-19781 for Citrix to gain access. APT41 exploited CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices.
APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Recently Exploited Vulnerabilities by MISSION2025 CVE-2017-0199 CVE-2017-0147 CVE-2017-11882 CVE-2021-44228
Recently Exploited Vulnerabilities by MISSION2025 CVE-2017-0199 CVE-2017-0147 CVE-2017-11882 CVE-2021-44228
37 more CVEs tied to this actor tracked in Mallory.
2,030 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a threat actor network connected to i-SOON in background discussion. The content provides no operational details or connection between APT41 and ZRON.
Mentioned only as a threat actor network connected to i-SOON in background discussion. No connection to ZRON or the current leaked dataset is established.
Used as a comparison with the less publicly scrutinized APT15. The article cautions against conflating these separate China-aligned operations and does not describe APT41-specific attacks, malware, or techniques.
Referenced as an example used to examine the campaigns, commercial incentives, and networks comprising China’s cyber ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.