The U.S. Department of Justice announced charges in September 2020 against five Chinese nationals accused of compromising more than 100 companies in operations attributed to APT41, associated with Winnti activity. Prosecutors alleged that the hackers stole sensitive information, conducted supply-chain attacks, and combined state-aligned espionage with financially motivated ransomware and cryptojacking. Three defendants allegedly operated through Chengdu 404 Network Technology, a security company serving Chinese public security and military customers. Earlier FireEye research characterized APT41 as a dual espionage and cybercrime operation, while Securelist documented Winnti’s connections to the gaming sector.
The alleged intrusions exploited vulnerabilities in internet-facing products from Citrix, Pulse Secure, D-Link, Cisco, and Zoho, as well as the Nostromo web server. Two Malaysian businessmen were separately indicted for allegedly monetizing digital gaming goods obtained through unauthorized access supplied by the hackers. Both were arrested in Malaysia; the five Chinese defendants remained at large when the charges were reported. The targeting highlights defensive priorities for enterprises: patch exposed infrastructure, scrutinize software supply-chain access, and monitor for data theft alongside ransomware and unauthorized cryptocurrency mining.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Wong Ong Hua and Ling Yang Ching were arrested in Malaysia on September 14. U.S. authorities alleged that their Sea Gamer Mall business monetized digital gaming goods obtained through unauthorized access provided by APT41 hackers.
Jiang Lizhi, Qian Chuan, and Fu Qiang were allegedly involved in ransomware attacks against a global nongovernmental organization, a U.S. real estate company, and a Taiwanese energy company.
CrowdStrike assessed that the group likely operated as an exploitation group for hire associated with Chinese government interests. It distinguished targeted intrusions as WICKED PANDA and financially motivated activity as WICKED SPIDER.
Jiang Lizhi, Qian Chuan, and Fu Qiang allegedly conducted APT41-linked hacking through Chengdu 404 Network Technology beginning in 2014. FireEye reported evidence of simultaneous cyberespionage and financially motivated cybercrime operations from that year onward.
According to court documents, Jiang Lizhi, Qian Chuan, and Fu Qiang had worked together since at least 2013. They also previously collaborated with Zhang Haoran and Tai Dailin.
Kaspersky reported tracking the group since 2012 under the Winnti name, which Symantec had assigned to malware associated with its attacks.
The DOJ announced charges against five Chinese nationals over attacks on more than 100 companies, alleging data theft, supply-chain compromises, ransomware, and cryptojacking; it also announced charges against two Malaysian businessmen over the gaming-goods conspiracy. All five Chinese defendants remained at large and had been added to the FBI's Cyber's Most Wanted list.
U.S. authorities charged Zhang Haoran and Tai Dailin separately before charging Jiang Lizhi, Qian Chuan, and Fu Qiang. The source does not specify the date of those initial charges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcefireeye.com
Open sourcesecurelist.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.