A41APT is a cyber-espionage threat cluster active from at least 2019 through 2021, with continued activity assessed into 2022, primarily targeting organizations in Japan and the overseas branches of Japanese companies. The actor is assessed with moderate confidence to be China-based. The name derives from a repeatedly observed workstation naming pattern used during intrusions. Reporting also notes overlaps with tooling and tradecraft associated with APT10/BRONZE RIVERSIDE, while cautioning that shared malware alone is insufficient for definitive attribution; some activity may involve multiple related groups. A41APT has specialized in compromising internet-facing infrastructure for initial access rather than relying primarily on spearphishing. Observed entry vectors include abuse of SSL-VPN appliances, exploitation of Microsoft Exchange Server vulnerabilities including ProxyShell, and use of stolen credentials. After access, the actor conducts reconnaissance and internal scanning, identifies administrative pathways, and moves laterally through enterprise environments using administrator accounts, RDP, PowerShell remoting, and remote execution utilities. The group has repeatedly targeted high-value internal systems such as Active Directory servers, file servers, antivirus management servers, backup servers, print servers, and fax servers. Post-compromise activity includes credential theft and directory discovery using tools such as Mimikatz, registry hive dumping, csvde, and related utilities. Defense evasion has included deletion of Windows event logs and use of memory-resident or fileless payloads. A41APT is notable for sustained use and evolution of multi-stage loader and RAT ecosystems including DESLoader or SigLoader, SodaMaster, P8RAT, FYAntiLoader, xRAT, HUI Loader, and at times Cobalt Strike stagers. DLL side-loading is a recurring execution method. In later activity, HUI Loader was used to load SodaMaster, including shellcode injection into svchost.exe. SodaMaster variants supported a broad command set including screenshot capture, keylogging control, credential theft from Outlook, execution of DLLs and shellcode, and process termination. Webshell deployment has also been observed, including China Chopper and Jackpot on internet-facing IIS or Exchange-adjacent systems. Persistence has been established through scheduled tasks that repeatedly launch legitimate binaries to side-load malicious components. The actor has also used compressed archiving tools for collection and exfiltration. Command-and-control practices have included frequent use of direct IP-based infrastructure with limited reuse patterns. Overall, A41APT is best characterized as a China-linked espionage actor focused on long-term access to Japanese enterprises and their affiliated overseas entities, using exploitation of exposed enterprise services, credential theft, DLL side-loading, stealthy persistence, and modular backdoors for sustained post-compromise operations and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Observations in 2021 ● Using known vulnerabilities ○ Pulse Connect Secure ○ FortiGate: CVE-2018-13379 ○ Cisco AnyConnect: CVE-2020-3125
Observations in 2021 ● Using known vulnerabilities ○ Pulse Connect Secure ○ FortiGate: CVE-2018-13379 ○ Cisco AnyConnect: CVE-2020-3125
Microsoft Exchange Server ... China Chopper webshell was installed after above activities ... Exploiting ProxyShell vulnerability
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ongoing campaign with evolving loaders/backdoors and Exchange exploitation, including webshell use and DLL sideloading to load SoadMaster.
Stealth APT campaign targeting Japanese companies, including overseas branches, using SSL-VPN abuse for initial access, DLL sideloading loaders, RDP-based lateral movement, credential theft, scheduled-task persistence, and event log deletion.
A long-running intrusion and espionage campaign targeting Japanese companies and their overseas branches via internet-facing systems, using vulnerabilities or stolen credentials, deploying loaders and backdoors such as SigLoader, SodaMaster, Jackpot, and HUI Loader, then conducting reconnaissance, lateral movement, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.