Threat Actor ProfileDouble Dragon

Double Dragon, also known as APT41, Winnti, or Barium is a Chinese threat actor known for conducting a mixture of state-sponsored espionage and financially motivated cybercrime. The Advanced Persistent Threat (APT) group is linked to China's People's Liberation Army (PLA), and although the true nature of this relationship cannot be verified, researchers have speculated that Double Dragon acts as a contract organisation tasked with advancing China's goals through stealthy, persistent cyber campaigns.

The group is best known for its relentless, profit-driven schemes against the video game industry, highly targeted espionage campaigns against Chinese adversaries, and a string of sophisticated supply chain attacks that have impacted organisations across the world. This page will provide an overview of the group's history and preferred tactics, as well as looking to the future to see how this persistent threat actor may evolve in the years to come.   

  • Aliases: APT41, Double Dragon, Blackfly, Grayfly, LEAD, BARIUM, WICKED SPIDER, WICKED PANDA, BRONZE ATLAS, Earth Baku, Amoeba, HOODOO, Brass Typhoon
  • Strategic motives: Espionage, Information Theft, Financial
  • Affiliation: Chinese People's Liberation Army
  • Cyber capabilities: ★★★★☆
  • Target sectors: Government, Healthcare, High Tech, Media, Energy, Telecommunications, Video Games, Cryptocurrency, Dissidents
  • Observed countries: Australia, Bahrain, Belarus, Brazil, Canada, Chile, China, Denmark, Finland, France, Georgia, Germany, Hong Kong, India, Indonesia, Italy, Japan, Malaysia, Mexico, Myanmar, Netherlands, Pakistan, Peru, Philippines, Poland, Qatar, Russia, Saudi Arabia, Singapore, South Africa, South Korea, Sri Lanka, Sweden, Switzerland, Taiwan, Thailand, Turkey, United Arab Emirates, United Kingdom, United States, Vietnam

Request a free membership to access our full research insights

Already a member? Login here

Origins, Motivations & Targets

Origins

The origins of Double Dragon trace back to the Network Crack Program Hacker group (NCPH), a Chinese entity linked to various for-hire cyber operations between 2006 and 2012. The NCPH was founded by Tan Dailin, also known as Wicked Rose, after he was scouted by the PLA's Sichuan Military Command Communication Department while studying at university. Following intensive state-sponsored training, Dailin transitioned into the role of a hacker for hire and worked with at least three other individuals to conduct cyber operations on behalf of NCPH clients.[1] The group was observed carrying out multiple zero-day attacks against US and Japanese entities by exploiting vulnerabilities in Microsoft Office products,[2] as well as breaching the US Department of Defence (DoD) and Pentagon several times in 2006.[3] During this time, NCPH members frequently detailed their activities on personal websites and in blog posts. This stopped in 2007, after which time the group moved further underground. By 2012, the NCPH's tactics, techniques and procedures (TTPs) had begun to overlap with other observed TTPs, prompting researchers to start tracking this new cluster as Double Dragon.[4] Since then, Double Dragon has grown into one of the most prolific and versatile threat actors in operation today. 

 

Motivations

Double Dragon splits its time between state-sponsored espionage, likely on behalf of the PLA, and financially motivated cybercrime. This dual-purpose approach is uncommon among Chinese threat actors, who are typically tracked as operating in one space or the other.[5] However, Double Dragon displays impressive versatility, its operations ranging from stealing video game currency to pulling off complex supply chain attacks involving high-profile targets. The group has been able to balance both objectives since about 2014.[6] Because of its unusual structure, some experts have speculated that Double Dragon operates as a legitimate contracting company, possibly comprised of multiple teams with different goals. Clear links have been made between Double Dragon and the company Chengdu Si Lingsi (404) Network Technology, commonly referred to as Chengdu 404. Established in 2014, Chengdu 404 claimed to provide white hat hacking and technology services to international clients. It is believed that the company was used as a front for Double Dragon, facilitating access to intellectual property and sensitive information under the guise of legitimate activities.[7] 

Double Dragon’s observed operating hours also support the idea of the group as a contract organisation. Research by Mandiant indicates that Double Dragon typically conducts state-sponsored espionage during normal work hours (the 996-schedule typical of Chinese tech workers[8]), while the group's financially motivated intrusions tend to occur much later at night.[9] The observed pattern might suggest the existence of two separate teams, one tasked with espionage and one with turning a profit, or that Double Dragon approaches cybercrime in a more ad-hoc manner, viewing it as a side-business that can be done outside of work hours. Without any further information available, it is only possible to speculate on the group’s structure and true motivations.  

 

Targets

Double Dragon has been observed targeting businesses in a wide range of sectors across the world, as well as selection of political and military organisations. It has launched cyberattacks against entities in more than 20 countries, including but not limited to: the United States, Japan, Taiwan, India, Thailand, China, Hong Kong, Mongolia, Indonesia, Vietnam, Bangladesh, Ireland, Brunei, Australia, Canada, France, and the United Kingdom.[10] The group’s targeting tends to differ quite significantly depending on the purpose of the operation, be that state-sponsored espionage or profit-driven cybercrime. Unsurprisingly, clear links can be made between Double Dragon's state-sponsored campaigns and CCP policy decisions. Since 1953, the CCP has issued a series of Five-Year plans, which encompass a range of social and economic development initiatives.[11] China‘s 13th and 14th Five Year plans (2016-2025) set targets for the domestic expansion of multiple sectors, including pharmaceuticals, biomedical devices, and high-tech. This coincided with Double Dragon attacks targeting the healthcare, medical research, and high-tech sectors.[12] The group's activities also appear to be broadly aligned with the Made in China 2025 policy and the Belt and Road Initiative.  These policies aim to increase China's geopolitical influence by strengthening its economy, reinforcing its military, and reducing its reliance on Western imports. Double Dragon is one of several Chinese threat actors working covertly to support these objectives.[13] The group has targeted a diverse array of sectors across the world and is most often leveraged for strategic intelligence gathering. The group is believed to use its global network of compromised systems as a "dragnet for information" that may be of interest to the CCP.[14] Recent trends show an increase in the targeting of foreign states’ critical infrastructure, raising questions over Double Dragon's ability to impact national security.[15]

Looking at Double Dragon's financially motivated hacking, the number of target industries shrinks considerably. Since its founding, the group has relentlessly targeted the video game sector, engaging in a range of activities that includes manipulating virtual currency, deploying ransomware, and infiltrating game production environments. Many of these activities, such as manipulating or stealing in-game currency, display a clear financial motive. However, the line between the group’s profit-driven and state-sponsored operations becomes blurry when considering the full spectrum of their activities against the video game sector. On multiple occasions, Double Dragon has been observed infiltrating game production environments, leveraging this access to inject malicious code into legitimate files for later distribution. These actions lack an immediate financial incentive and can instead been viewed as broadly malicious activities intended to support future campaigns. It appears that Double Dragon’s experience of accessing game production environments has actively supported the group’s state-sponsored work, allowing them to develop the TTPs that would be used in later supply chain compromises.[16] Similarly, the line between Double Dragon’s state-sponsored and financially motivated operations blurs when looking at the tools they use. Notably, the group has been observed using non-public malware, which is associated with multiple China-nexus threat actors, in operations that seem to fall outside the scope of their state sponsored campaigns.[17] This raises questions about the CCP’s tacit support for Double Dragon’s (seemingly) profit driven targeting of the video game sector. Why would the CCP tolerate activities with an explicit financial motive, which draw increased scrutiny to the group? Further, why would the CCP tolerate the use of malware that is typically reserved for espionage in operations that appear to be for personal gain? Hunt & Hackett believes this surprising duality highlights the group’s strategic importance to the Chinese state. Double Dragon is an extremely resourceful threat actor that can be characterised by high levels of innovation and a willingness to adapt its techniques until its objectives are met. Our observations suggest that Double Dragon may use the video game sector as an innovation sandbox, so to speak, where it can sharpen its tools for later use in state-sponsored campaigns. From the perspective of the CCP, the benefits of these operations likely outweigh the risks associated with their explicitly profit driven activities. As noted by Mandiant researchers, the unusual relationship between Double Dragon and the CCP underscores a "blurred line between state power and crime that lies at the heart of threat ecosystems."[18]

SWOT analysis

Strengths, weaknesses, opportunities & threats

Strengths

  • Well resourced due to state support and for-profit activities
  • Access to a diverse range of tools and malware
  • Financially motivated operations appear to be tolerated by the Chinese government

Weaknesses

  • Double Dragon has come under increased scrutiny from researchers and law enforcement in recent years, particularly after targeting US state governments and the critical national infrastructure of Asian states

Opportunities

  • Double Dragon has proven its capabilities when it comes to creating custom tools and malware.
  • Advancements in AI and other emerging technologies allows Double Dragon to increase the sophistication of its attacks.

Threats

  • International legal action (as in the case of US indictments)
  • Possibility of action from the Chinese government in relation to use of espionage-associated malware in profit-driven operations

Campaigns Overview

Operation ShadowPad

2017

In a 2017 operation dubbed "ShadowPad", Double Dragon leveraged a new modular remote access trojan to compromise the supply chain of NetSarang, an ISP that supplies server management software to hundreds of companies in the financial services, education, telecoms, manufacturing, energy, and transportation sectors. NetSarang maintains headquarters in the United States and South Korea. During this operation, Double Dragon inserted malicious code into a software update package and signed it with a valid NetSarang certificate. After the infected software update was installed, the malicious module would send basic information about the victim's system (such as the username, domain name, and host name) as part of DNS queries to specific domains (its Command and Control (C2) server). After obtaining a decryption key from the initial DNS communications, Double Dragon had the ability to initiate a second-stage shellcode, allowing it to selectively activate the payload on specific victim systems.[19] 

Operation ShadowPad came to light when Kaspersky was approached by one of its partners, a financial institution, that had noticed suspicious DNS requests coming from a system involved in the processing of financial transactions. Further investigation revealed the malicious module hiding inside a recent version of NetSarang's software. Kaspersky notified NetSarang and a patch was quickly released, limiting the incident's impact. Notably, second-stage malware activation was only observed on one victim system in Hong Kong.[20] At the time, Operation ShadowPad was considered to be one of the largest observed supply chain attacks, with the potential to impact hundreds of organisations globally. This would not be the last time that Double Dragon would use stolen code signing keys and certificates to infect legitimate software packages with malware, with the aim of compromising major supply chains.[21]

Operation ShadowHammer

2018

Almost a year after the NetSarang supply chain attack, Double Dragon compromised a utility used to update ASUS computers in a highly targeted operation known as ShadowHammer. Once again, the compromised software was signed with a legitimate certificate, allowing the attack to go undetected for several months. Research by Kaspersky indicates that the incident began in June 2018 and appears to have been terminated by the attackers in November 2018, although it remained undiscovered until January 2019.[22] Up to 1 million systems are believed to have installed the update, but the mechanism was only designed to execute and retrieve second-stage malware on a shortlist of approximately 600 systems. To achieve this, Double Dragon hardcoded a list of MAC addresses in the trojanized samples. According to FireEye, at least one telecom company was identified as a target of this campaign.[23] Although the victim pool was (by design) relatively small, the fact that Double Dragon was able to successfully install backdoors in up to a million machines worldwide highlights the capabilities of the group. 

Operation CuckooBees

2019 - 2021

Operation CuckooBees has been described as one of the "largest IP theft campaigns of its kind coming from China".[24] During this multi-year campaign, Double Dragon stole intellectual property and sensitive data from dozens of large companies in the defence, energy, biotech, aerospace and pharmaceutical sectors across multiple continents. The group also obtained data that could be used in future attacks, such as information related to the companies’ business units, network architecture, user accounts and credentials, employee emails, and customer data. Double Dragon gained initial access to the targeted organisations by exploiting multiple vulnerabilities in an ERP (Enterprise Resource Planning) platform. The attackers installed persistence in the form of a WebShell and began conducting reconnaissance and credential dumping, enabling lateral movement within the network. An undocumented malware strain, DEPLOYLOG, was used in the campaign, as well as updated versions of malware such as Spyder Loader, PRIVATELOG, and WINNKIT.[25]  Operation CuckooBees is believed to have started in 2019 and was discovered by researchers at Cybereason in 2021.  

The group's ability to operate under the radar for multiple years underscores the stealth and sophistication of Double Dragon's attacks. The group is adept at blending into the noise of normal network traffic by disguising malicious behaviour as legitimate activities. The group also exhibits an advanced understanding of evasion techniques, encrypting communication channels and regularly updating tactics to evade signature-based detection. Drawing on its experience of targeting the video game industry, Double Dragon can quickly move laterally within compromised networks, allowing it to navigate and escalate privileges without raising alarms. This combination of tailored tools, evasion tactics, and lateral movement capabilities enables Double Dragon to maintain a persistent and covert presence in targeted environments, as demonstrated in the case of Operation CuckooBees.[26]

US State Government Breach

2021

In 2021, Double Dragon successfully compromised at least six US state government networks by exploiting vulnerable Internet facing web applications, which included the utilization of a zero-day vulnerability within the USAHerds application and the notorious Log4j vulnerability. The group conducted .NET deserialization attacks to compromise the majority of the web applications but were also observed exploiting SQL injection and directory traversal vulnerabilities in some cases. The group demonstrated remarkable adaptability and persistence, often shifting their tactics during this campaign. Mandiant, who was working with one of the impacted state governments, observed Double Dragon re-compromising previously targeted networks by exploiting new vulnerabilities. In two other cases, Mandiant began an investigation at one state agency only to find that Double Dragon had also compromised a separate, unrelated agency in the same state.[27] This is the most high-profile and widely publicized operation Double Dragon has conducted against US institutions. Although their specific objectives remain unclear, this activity aligns with the group's mandate of state-sponsored espionage and strategic intelligence gathering.  

Hong Kong Government Breach

2022

In May 2022, researchers at Cybereason discovered a Double Dragon campaign targeting government organisations in Hong Kong, believed to be a continuation of Operation CuckooBees. The campaign reportedly started in 2019 and attackers remained inside compromised networks for more than a year in some cases. During this time, the group deployed custom-built Spyder Loader malware on multiple target networks and leveraged many of the same TTPs used in Operation CuckooBees.[28] Interestingly, several different variants of Spyder Loader have been observed over the course of both campaigns. Once again, the group proved its ability to innovate and adapt until it achieved its objectives.[29] Symantec, who uncovered the campaign in 2022, assessed that intelligence collection was likely the goal of this operation.[30]

Targeting of Asian critical national infrastructure

2023

In 2023, the national grid of an (undisclosed) Asian country was compromised in an attack attributed to Double Dragon. Attackers are believed to have remained inside the organisation's network for six months, during which time they stole credentials and compromised several computers in the organisation's network. The first sign of malicious activity was observed on February 28, 2023, when ShadowPad malware was executed on a single computer. Activity resumed on May 16, when a legitimate Windows extension, oleview.exe, was used to facilitate lateral movement. Shortly after, PackerLoader, which is used to load and execute shellcode, was deployed and a legitimate binary named displayswitch.exe was executed. It was likely being used to perform DLL side-loading. Over the next few months, the attackers harvested credentials and executed malware on several computers in the network. The last sign of Double Dragon activity was observed on August 3, when the attackers returned and attempted to dump credentials using a renamed version of ProcDump. Minutes later, the attackers also attempted to dump credentials from the Windows registry.[31] Symantec, who investigated the incident, attributed the attack to a group it tracks as "Redfly." Symantec believes Redfly is a subset of Double Dragon that focuses exclusively on targeting critical national infrastructure.[32]

More detailed information about this actor?

Already a member? Login here

Double Dragon in the Netherlands

In 2020, researchers uncovered a campaign where more than 50 computers had been infected with ShadowPad malware, later attributing the attack to Double Dragon. A Dutch audit firm was among the targeted organisations, in addition to companies based in Russia, Germany and the US.[66] Further details about this case have not been publicly disclosed, and it is unclear why this company was targeted.  

Although we have limited information concerning the group's operations in the Netherlands, we do know that Dutch organisations are frequently targeted for intellectual property, trade secrets, R&D and other sensitive information that might benefit the threat actor or relevant nation state. China actively uses cyberspace to advance its ambitions of strengthening its global power, by focusing on (military) modernization, economic growth, domestic stability and territorial integrity.[67] Because the Netherlands is known for having a high degree of technological innovation and a strong economy, Dutch enterprises are seen as attractive targets. This was demonstrated by a report published on February 6, 2024, by the Dutch Military Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) about a new type of malware found on a network of the Dutch armed forces. They assessed with high confidence that the malware, named COATHANGER, was installed by a state-sponsored actor from China, who was found spying on an unclassified military R&D unit.[68] This case was viewed as part of a wider trend of Chinese political espionage in the Netherlands. To learn more about China’s cyber campaigns against the Netherlands, read Hunt & Hackett's China threat profile.

Trends

In recent years, Double Dragon has become the target of international legal action. In August 2019 and August 2020, a US court issued two separate indictments against five suspected members of the group - Zhang Haoran, Tan Dailin, Qian Chuan, Fu Qiang, and Jiang Lizhi [69] - on various charges, including unauthorized access to protected computers, aggravated identity theft, money laundering, and wire fraud. The charges stemmed from multiple campaigns that enabled the theft of source code, code signing certificates, customer account data, and sensitive business information. Shortly after, an additional indictment was issued for two Malaysian businessmen who were accused of conspiring with Double Dragon to sell stolen virtual currency on an underground market. They were arrested in Sitiawan in September 2020.[70] Although these indictments are unlikely to result in the arrest of any Double Dragon members, given their protection from the Chinese state, it will be interesting to see how future legal actions against the group take shape.  

Taking a broader view, it is interesting to note the steady evolution in the tactics employed by Chinese APTs since the 2010s. Chinese espionage operations have become increasingly sophisticated and stealthy, with threat actors often evading detection for long periods and adapting their techniques as time goes on. Researchers have observed an increasing tendency to use living-off-the-land (LOTL) techniques, software supply chain compromise, and modular malware. Additionally, zero-day exploitation by Chinese APTs has increasingly focused on security, networking, and virtualization technologies, as targeting these Internet facing devices provides tactical advantages for obtaining and maintaining covert access to victim networks.[71] This was seen in the case of a Chinese threat actor targeting the Dutch armed forces, when a firewall solution (FortiGate) was exploited before COATHANGER malware was installed. These general trends align with Hunt & Hackett's analysis of Double Dragon's evolution and modus operandi.  

Conclusions & Future Implications

As the name suggests, Double Dragon's dual-purpose nature defines the group, setting it apart from other APTs. As demonstrated by both espionage and cybercrime campaigns, Double Dragon is a well-resourced, creative, skilful threat actor that appears to play an important role in China’s cyber ambitions. Based on our analysis, Hunt & Hackett views Double Dragon as the ‘innovator’ within the pool of China-nexus threat actors, having demonstrated an immense aptitude for creating new tools and adapting techniques until it achieves its objectives. The group operates with incredible stealth, often remaining inside compromised systems for long periods of time and obfuscating malicious activities inside normal network traffic. What's more, Double Dragon has been observed using increasingly sophisticated tactics, techniques and procedures in recent years. This underscores their status as one of the most sophisticated APTs in operation today. 

Given China's ambitions of global hegemony, it is likely that Double Dragon will remain a persistent threat for the foreseeable future. The group's state-sponsored campaigns are likely to remain in alignment with China's economic and military goals, while operations that fall outside the scope of state-sponsored work will provide a dual opportunity for financial gain and innovation. As the group continues to evolve and expand its capabilities, the international community should remain vigilant, continuously updating detection measures, sharing technical information, and increasing awareness of the threats posed by state-backed espionage.  

Sources

1. https://krebsonsecurity.com/wp-content/uploads/2012/11/WickedRose_andNCPH.pdf

2. Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack - Security Boulevard

3. https://ict.org.il/UserFiles/Chinese%20Hacker%20Groups.pdf

4. https://www.cyfirma.com/outofband/the-origins-of-apt-41-and-shadowpad-lineage/

5. https://www.mandiant.com/sites/default/files/2022-02/rt-apt41-dual-operation.pdf

6. https://socradar.io/5-facts-you-should-know-about-apt41-double-dragon/

7. https://intrusiontruth.wordpress.com/2022/07/22/chengdu-404/

8. https://www.hcamag.com/asia/specialisation/employee-engagement/chinas-966-work-culture-would-you-adopt-the-model/421993

9. https://services.google.com/fh/files/misc/apt41-a-dual-espionage-and-cyber-crime-operation.pdf

10. https://duo.com/decipher/attack-campaign-by-apt41-targeted-companies-in-20-countries

11. https://www.britannica.com/topic/First-Five-Year-Plan-Chinese-economics

12. APT41 Chinese Cyber Threat Group | Espionage & Cyber Crime (mandiant.com) 

13. https://www.datacenterdynamics.com/en/opinions/cyber-threat-implications-of-chinas-five-year-plan/

14. https://intrusiontruth.wordpress.com/2022/07/22/chengdu-404/

15. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/critical-infrastructure-attacks

16. https://www.mandiant.com/resources/reports/apt41-double-dragon-dual-espionage-and-cyber-crime-operation

17. https://www.mandiant.com/resources/reports/apt41-double-dragon-dual-espionage-and-cyber-crime-operation

18. https://www.mandiant.com/resources/blog/apt41-dual-espionage-and-cyber-crime-operation

19. https://www.kaspersky.com/about/press-releases/2017_shadowpad-how-attackers-hide-backdoor-in-software-used-by-hundreds-of-large-companies-around-the-world

20. https://www.kaspersky.com/about/press-releases/2017_shadowpad-how-attackers-hide-backdoor-in-software-used-by-hundreds-of-large-companies-around-the-world

21. https://www.secureworks.com/research/shadowpad-malware-analysis

22. https://nl.sentinelone.com/wp-content/uploads/pdf-gen/1666880647/asus-shadowhammer-episode-a-custom-made-supply-chain-attack.pdf

23. https://www.reuters.com/article/us-china-cyber-moonlighters/chinese-government-hackers-suspected-of-moonlighting-for-profit-idUSKCN1UX1JE/

24. https://www.cybereason.com/press/cybereason-uncovers-global-chinese-espionage-campaign-targeting-manufacturers-in-north-america-europe-and-asia

25. (1) New Messages! (cybereason.com) 

26. Report2020CrowdStrikeGlobalThreatReport.pdf

27. APT41 Targeting U.S. State Government Networks | Mandiant

28. https://www.bleepingcomputer.com/news/security/hackers-compromised-hong-kong-govt-agency-network-for-a-year/

29. https://therecord.media/hong-kong-govt-orgs-targeted-for-over-a-year-with-spyder-loader-malware-report

30. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyder-loader-cuckoobees-hong-kong

31. Redfly espionage hackers continue to strike critical infrastructure, as Asian national grid compromised - Industrial Cyber

32. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/apt41-indictments-china-espionage

33. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

34. Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques (cybereason.com) 

35. https://www.linkedin.com/pulse/from-friend-foe-how-apt41-weaponized-googles-red-teaming-tool/

36. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

37. Windows Management Instrumentation, Technique T1047 - Enterprise | MITRE ATT&CK®

38. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

39. Hijack Execution Flow, Technique T1574 - Enterprise | MITRE ATT&CK® 

40. APT41 Targeting U.S. State Government Networks | Mandiant 

41. https://attack.mitre.org/techniques/T1543/

42. rt-apt41-dual-operation.pdf (mandiant.com) 

43. APT41 Targeting U.S. State Government Networks | Mandiant

44. APT41 Initiates Intrusion Campaign Using Multiple Exploits (mandiant.com) 

45. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

46. APT41 Targeting U.S. State Government Networks | Mandiant 

47. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

48. APT41, Wicked Panda, Group G0096 | MITRE ATT&CK® 

49. https://www.group-ib.com/blog/apt41-world-tour-2021/

50. https://techhq.com/2021/11/fbi-most-wanted-cyberattackers-are-blueprint-for-other-hacker-groups/

51. https://assets-us-01.kc-usercontent.com/994513b8-133f-0003-9fb3-9cbe4b61ffeb/28a1df52-f8bd-4cdf-9337-ce101760b501/aid_field_file__e75a013c42c6fc66c216bb8c57bb6fc2.pdf

52. APT41’s cyber attack methods are a blueprint for hacker groups- TechHQ 

53. https://www.mandiant.com/sites/default/files/2022-02/rt-apt41-dual-operation.pdf

54. https://www.mandiant.com/resources/blog/apt41-dual-espionage-and-cyber-crime-operation

55. https://www.silicon.co.uk/workspace/plugx-rat-malware-creator-is-an-it-company-director-92780

56. https://www.secureworks.com/blog/bronze-president-targets-government-officials

57. https://intrusiontruth.wordpress.com/category/apt41/

58. https://www.computerweekly.com/news/252524710/Chinese-APT-using-PlugX-malware-on-espionage-targets

59. https://www.secureworks.com/blog/bronze-president-targets-government-officials

60. https://www.fbcinc.com/source/virtualhall_images/NLIT_June_21/Recorded_Future/cta-2021-0228.pdf

61. https://www.secureworks.com/research/shadowpad-malware-analysis

62. ShadowPad | A Masterpiece of Privately Sold Malware in Chinese Espionage - SentinelLabs (sentinelone.com) 

63. https://www.group-ib.com/blog/apt41-world-tour-2021/

64. https://www.darkreading.com/remote-workforce/china-apt41-baffling-approach-cobalt-strike-payload

65. https://attack.mitre.org/techniques/T1543/

66. https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/shadowpad-new-activity-from-the-winnti-group/

67. https://www.cnas.org/publications/reports/warring-state-chinas-cybersecurity-strategy

68. https://therecord.media/dutch-find-chinese-hackers-networks-fortinet

69. https://www.fbi.gov/wanted/cyber/apt-41-group

70. https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer

71. https://www.mandiant.com/resources/blog/chinese-espionage-tactics

Learn more about our threat research?

Get in touch