The U.S. Department of Justice charged seven international defendants, including five alleged members of APT41, over computer intrusion campaigns that hit more than 100 victims worldwide. Prosecutors said the group targeted universities, software developers, telecommunications providers, social media companies, video game firms, nonprofits, and foreign governments, stealing source code, customer account data, and personally identifiable information while pursuing both espionage and financial gain. The indictments describe activity ranging from supply-chain compromises and credential theft to fraud involving in-game currency and other monetization schemes.
Reporting tied the charged activity to broader APT41 operations, including ColdLock ransomware attacks against Taiwanese organizations, especially in the energy sector. In those intrusions, attackers were observed using Active Directory Group Policy, scheduled tasks, SMB, PowerShell, customized loaders, and Cobalt Strike to move laterally and deploy ransomware. Trend Micro said related activity also affected energy, retail, and telecommunications organizations in Southeast Asia, with infrastructure overlaps and targeting patterns suggesting links between criminal operations and Chinese state-aligned espionage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On September 16, 2020, the U.S. Justice Department announced charges against five Chinese citizens tied to APT41 for hacking crimes connected to global intrusion campaigns. The department also said two Malaysian citizens were arrested for aiding the hackers, while the five Chinese nationals remained fugitives.
Trend Micro identified overlapping indicators and command-and-control infrastructure suggesting related incidents affecting energy, retail, and telecom companies, mainly in Southeast Asia. The company also observed password-dumping and HTTP tunneling tools used before ransomware deployment about one month later.
Trend Micro investigated a ColdLock ransomware incident affecting the energy industry in Taiwan. In that case, the attackers used compromised Active Directory credentials, modified Group Policy Objects to push scheduled tasks, spread via SMB and an internal IIS service, and deployed customized loaders and Cobalt Strike.
According to the indictments described by the Justice Department, APT41 targeted more than 100 institutions in the United States and abroad, including video game companies, telecommunications firms, universities, non-profits, and software providers. The campaign involved espionage and profit-driven activity, including theft of source code, customer account data, and personally identifiable information.
4 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcejustice.gov
Open sourcesymantec-enterprise-blogs.security.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.