All actors

APT41

Also reported as Brass Typhoon, BARIUM, TG-2633, Leopard Typhoon, Double Dragon and 30 other names. Linked to China by four sources.

Reports
1,151
Last reported
Known CVEs
353
Techniques in ATT&CK
82
Origin
China
ID
G0096
Merge evidence
52 alias matches

Reports per quarter

  1. 2012 Q4: 1 report
  2. 2013 Q1: 1 report
  3. 2013 Q2: no reports
  4. 2013 Q3: 1 report
  5. 2013 Q4: no reports
  6. 2014 Q1: no reports
  7. 2014 Q2: no reports
  8. 2014 Q3: 1 report
  9. 2014 Q4: 1 report
  10. 2015 Q1: 8 reports
  11. 2015 Q2: 3 reports
  12. 2015 Q3: 3 reports
  13. 2015 Q4: 2 reports
  14. 2016 Q1: no reports
  15. 2016 Q2: 1 report
  16. 2016 Q3: 1 report
  17. 2016 Q4: 1 report
  18. 2017 Q1: 3 reports
  19. 2017 Q2: 5 reports
  20. 2017 Q3: 6 reports
  21. 2017 Q4: 4 reports
  22. 2018 Q1: 4 reports
  23. 2018 Q2: 4 reports
  24. 2018 Q3: 6 reports
  25. 2018 Q4: 4 reports
  26. 2019 Q1: 12 reports
  27. 2019 Q2: 17 reports
  28. 2019 Q3: 18 reports
  29. 2019 Q4: 28 reports
  30. 2020 Q1: 26 reports
  31. 2020 Q2: 28 reports
  32. 2020 Q3: 36 reports
  33. 2020 Q4: 54 reports
  34. 2021 Q1: 78 reports
  35. 2021 Q2: 73 reports
  36. 2021 Q3: 89 reports
  37. 2021 Q4: 69 reports
  38. 2022 Q1: 79 reports
  39. 2022 Q2: 80 reports
  40. 2022 Q3: 61 reports
  41. 2022 Q4: 29 reports
  42. 2023 Q1: 33 reports
  43. 2023 Q2: 19 reports
  44. 2023 Q3: 26 reports
  45. 2023 Q4: 21 reports
  46. 2024 Q1: 16 reports
  47. 2024 Q2: 26 reports
  48. 2024 Q3: 29 reports
  49. 2024 Q4: 15 reports
  50. 2025 Q1: 17 reports
  51. 2025 Q2: 12 reports
  52. 2025 Q3: 12 reports
  53. 2025 Q4: 8 reports
  54. 2026 Q1: 8 reports
  55. 2026 Q2: 71 reports
  56. 2026 Q3: 1 report
Dated reports, 2012 Q4 to 2026 Q3.

Techniques seen in the last two years

Show all 290 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 18 techniques Show fewer

CVEs named in reports

Show all 353 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Bankshot (Malware Family)

    date ORKL added it fromORKL

  2. StoneDrill (Malware Family)

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. ShadowPad (Malware Family)

    date ORKL added it fromORKL

Show all 1,151 reports Show fewer
  1. Crimson RAT (Malware Family)

    date ORKL added it fromORKL

  2. Ghost RAT (Malware Family)

    date ORKL added it fromORKL

  3. Oblique RAT (Malware Family)

    date ORKL added it fromORKL

  4. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  5. METALJACK (Malware Family)

    date ORKL added it fromORKL

  6. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

  7. SUNBURST (Malware Family)

    date ORKL added it fromORKL

  8. CHINACHOPPER (Malware Family)

    date ORKL added it fromORKL

  9. QakBot (Malware Family)

    date ORKL added it fromORKL

  10. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  11. REvil (Malware Family)

    date ORKL added it fromORKL

  12. MimiKatz (Malware Family)

    date ORKL added it fromORKL

  13. ZXShell (Malware Family)

    date ORKL added it fromORKL

  14. PlugX (Malware Family)

    date ORKL added it fromORKL

  15. PowGoop (Malware Family)

    date ORKL added it fromORKL

  16. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  17. NjRAT (Malware Family)

    date ORKL added it fromORKL

  18. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  19. Ryuk (Malware Family)

    date ORKL added it fromORKL

  20. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  21. MoonWalk | ThreatLabz

    file creation date fromORKL

  22. APT41 Has Arisen From the DUST | Google Cloud Blog

    file creation date fromORKL

  23. DodgeBox | ThreatLabz

    file creation date fromORKL

  24. i-soon-data-leaks-jp

    date ORKL added it fromORKL

  25. i-soon-data-leaks-en

    date ORKL added it fromORKL

  26. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  27. Daggerfly- APT Actor Targets Telecoms Company in Africa

    date in the title fromORKL

  28. How Microsoft names threat actors

    date in the title fromORKL

  29. Blackfly: Espionage Group Targets Materials Technology

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  30. The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  31. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  32. New Wave of Espionage Activity Targets Asian Governments

    date in the title fromORKL

  33. RedSense

    Malpedia library date fromORKL

  34. APT41 World Tour 2021 on a tight schedule

    date in the title fromORKL

  35. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  36. APT41- A Case Sudy

    date in the title fromORKL

  37. RedSense

    Malpedia library date fromORKL

  38. APT41 A Case Sudy

    date in the CCS '25 data Intrusion Truth fromCCS '25 data

  39. CERT-UA

    Malpedia library date fromORKL

  40. CERT-UA

    Malpedia library date fromORKL

  41. RedSense

    Malpedia library date fromORKL

  42. PowerPoint Presentation

    Malpedia library date Hughes, Jennifer fromORKLCCS '25 data

  43. Gamer Cheater Hacker Spy

    date in the title fromORKL

  44. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  45. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  46. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  47. RedSense

    Malpedia library date fromORKL

  48. CERT-UA

    Malpedia library date fromORKL

  49. A Summary of APT41 Targeting U.S. State Governments

    file creation date Mandiant fromORKL

  50. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  51. 2021trends.pdf

    Malpedia library date fromORKL

  52. RedSense

    Malpedia library date fromORKL

  53. ShadowPad Malware Analysis

    date in the title fromORKL

  54. ShadowPad Malware Analysis _ Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  55. eset_threat_report_t32021

    file creation date fromORKL

  56. MoonBounce_ the dark side of UEFI firmware _ Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  57. MoonBounce- the dark side of UEFI firmware

    date in the title fromORKL

  58. Delving Deep: An Analysis of Earth Lusca's Operations

    Malpedia library date fromORKL

  59. Winnti is Coming - Evolution after Prosecution

    date in the title fromORKL

  60. PseudoManuscrypt- a mass-scale spyware attack campaign

    date in the title fromORKL

  61. It’s a BEE! It’s a… no, it’s ShadowPad.

    date in the title fromORKL

  62. FINDING BEACONS IN THE DARK 1650728751599

    Malpedia library date BlackBerry fromORKLCCS '25 data

  63. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  64. APT trends report Q3 2021

    date in the title fromORKL

  65. Drawing a Dragon- Connecting the Dots to Find APT41

    date in the title fromORKL

  66. RedSense

    Malpedia library date fromORKL

  67. FamousSparrow_ A suspicious hotel guest _ WeLiveSecurity

    date in the CCS '25 data ESET fromORKLCCS '25 data

  68. eset_threat_report_t22021

    file creation date fromORKL

  69. FamousSparrow- A suspicious hotel guest

    date in the title fromORKL

  70. Report2021ThreatHunting

    file creation date fromORKL

  71. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  72. The SideWalk may be as dangerous as the CROSSWALK

    date in the title fromORKL

  73. Shadowpad

    Malpedia library date SentinelOne fromORKLCCS '25 data

  74. Top Routinely Exploited Vulnerabilities

    date in the title fromORKL

  75. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  76. BIOPASS RAT New Malware Sniffs Victims via Live Streaming

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  77. Презентация PowerPoint

    Malpedia library date fromORKL

  78. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  79. Geopolitical nation-state threat actor overview June 2021

    date in the title fromORKL

  80. Cobalt Strike- Favorite Tool from APT to Crimeware

    date in the title fromORKL

  81. Big airline heist_ APT41 likely behind massive supply chain attack

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  82. Hacker Lexicon- What Is a Supply Chain Attack-

    date in the title fromORKL

  83. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  84. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  85. APT Threat Landscape of Taiwan in 2020

    date in the title fromORKL

  86. CTIR_casestudy_2.pdf

    file creation date fromORKL

  87. CTIR_casestudy_1.pdf

    file creation date fromORKL

  88. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  89. mtrends-2021

    file creation date fromORKL

  90. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  91. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  92. Linux Backdoor RedXOR Likely Operated by Chinese Nation-State

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  93. Exchange servers under siege from at least 10 APT groups

    date in the title fromORKL

  94. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  95. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  96. operation-nightscout-supply-chain-attack-online-gaming-asia

    date in the CCS '25 data ESET fromORKLCCS '25 data

  97. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  98. ptsecurity.com-Higaisa or Winnti APT41 backdoors old and new

    file creation date fromORKL

  99. Higaisa or Winnti- APT41 backdoors, old and new

    date in the title fromORKL

  100. Sunburst backdoor – code overlaps with Kazuar

    date in the title fromORKL

  101. securelist.com-Sunburst backdoor code overlaps with Kazuar

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  102. China cyber attacks- the current threat landscape

    date in the title fromORKL

  103. Analyzing Cobalt Strike for Fun and Profit

    date in the title fromORKL

  104. From ThreatHunting to Campaign Tracking

    date in the title fromORKL

  105. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  106. PowerPoint Presentation

    file creation date Ganesan, Brittany (OS/ASA) (CTR) fromORKL

  107. Hunting for Barium using Azure Sentinel

    date in the title fromORKL

  108. APT_trends_report_Q3_2020_Securelist

    file creation date fromORKL

  109. APT trends report Q3 2020

    date in the title fromORKL

  110. Study of the ShadowPad APT backdoor and its relation to PlugX

    Malpedia library date The Intercept fromORKLCCS '25 data

  111. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  112. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  113. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  114. winnti-2020-rus.pdf

    file creation date fromORKL

  115. An overview of targeted attacks and APTs on Linux

    date in the title fromORKL

  116. 2020.09.29_ShadowPad - new activity from the Winnti group

    Malpedia library date fromORKL

  117. What even is Winnti-

    date in the title fromORKL

  118. APT 41

    date in the CCS '25 data Council on Foreign Relations fromCCS '25 data

  119. cybersecurity-threatscape-2020-q1-eng

    file creation date fromORKL

  120. BRONZE VINEWOOD Targets Supply Chains _ Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  121. BRONZE VINEWOOD Targets Supply Chains

    date in the title fromORKL

  122. Hacker Lexicon- What Is a Supply Chain Attack-

    date in the title fromORKL

  123. No “Game over” for the Winnti Group _ WeLiveSecurity

    date in the CCS '25 data ESET fromORKLCCS '25 data

  124. T1055 Process Injection

    date in the title fromORKL

  125. ESET_Threat_Report_Q12020

    date in the CCS '25 data ESET fromORKLCCS '25 data

  126. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  127. WINNTI GROUP_ Insights From the Past

    date in the CCS '25 data QuoIntelligence fromORKLCCS '25 data

  128. WINNTI GROUP- Insights From the Past

    date in the title fromORKL

  129. Catching APT41 exploiting a zero-day vulnerability

    date in the title fromORKL

  130. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  131. report-bb-decade-of-the-rats

    file creation date fromORKL

  132. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  133. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  134. mtrends-2020

    file creation date fromORKL

  135. Winnti Group targeting universities in Hong Kong

    date in the CCS '25 data ESET fromORKLCCS '25 data

  136. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  137. MESSAGETAP- Who’s Reading Your Text Messages-

    date in the title fromORKL

  138. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  139. MESSAGETAP_ Who’s Reading Your Text Messages

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  140. Shikata Ga Nai Encoder Still Going Strong

    date in the title fromORKL

  141. Winnti Group’s skip‑2.0_ A Microsoft SQL Server backdoor

    date in the CCS '25 data ESET fromORKLCCS '25 data

  142. LOWKEY_ Hunting for the Missing Volume Serial ID

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  143. ESET_Winnti

    Malpedia library date fromORKL

  144. HELO Winnti_ Attack or Scan

    file creation date fromORKL

  145. HELO Winnti- Attack or Scan-

    date in the title fromORKL

  146. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  147. GAME OVER: Detecting and Stopping an APT41 Operation

    file creation date FireEye fromORKL

  148. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  149. GAME OVER- Detecting and Stopping an APT41 Operation

    date in the title fromORKL

  150. blog_APT41

    file creation date fromORKL

  151. APT41- A Dual Espionage and Cyber Crime Operation

    date in the title fromORKL

  152. report_APT41

    file creation date fromORKL

  153. TLP-WHITE-CERT-EU-MEMO-190725-1.pdf

    file creation date fromORKL

  154. Winnti_ Attacking the Heart of the German Industry

    date in the CCS '25 data BR and NDR fromORKLCCS '25 data

  155. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  156. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  157. TeamViewer Confirms Undisclosed Breach From 2016

    date in the title fromORKL

  158. Bayer points finger at Wicked Panda in cyberattack

    date in the title fromORKL

  159. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  160. Operation ShadowHammer

    file creation date fromORKL

  161. Operation ShadowHammer

    date in the title fromORKL

  162. Report2019GlobalThreatReport

    file creation date fromORKL

  163. Gaming-Industry.Asia

    date in the CCS '25 data ESET fromORKLCCS '25 data

  164. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  165. Burning Umbrella

    date in the CCS '25 data 401TRG fromORKLCCS '25 data

  166. Advanced Persistent Threat Groups

    date in the title fromORKL

  167. Analysing a 10-Year-Old SNOWBALL

    date in the title fromORKL

  168. Recent Winnti Infrastructure and Samples _ ClearSky Cybersecurity

    date in the CCS '25 data ClearSky fromORKLCCS '25 data

  169. Winnti Evolution - Going Open Source

    date in the CCS '25 data ProtectWise fromORKLCCS '25 data

  170. security_report_20160613.pdf

    Malpedia library date fromORKL

  171. Newcomers in the Derusbi family

    Malpedia library date fromORKL

  172. VB2015_Catching_the_silent_whisper

    Malpedia library date mpun@fortinet.com, ericleung@fortinet.com, ntan@fortinet.com fromORKL

  173. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  174. Animal Farm APT and the Shadow of French Intelligence

    date in the title fromORKL

  175. APT17_Report.pdf

    Malpedia library date fromORKL

  176. Animals in the APT Farm

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  177. Animals in the APT Farm

    date in the title fromORKL

  178. casper-malware-babar-bunny-another-espionage-cartoon

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  179. Babar: espionage software finally found and put under the microscope

    date in the CCS '25 data G DATA fromORKLCCS '25 data

  180. Threat Group-3279 Targets the Video Game Industry | Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

Newest first. Details opens the report in Explore.