Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT41

🇨🇳APT41

🇨🇳 APT41 is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 26 detection use cases to this actor across 95 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-02-26 to 2026-02-26.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0096) ↗
26Use cases
1Articles
95Techniques
5IOCs

Known aliases

APT41BARIUMWicked PandaWinnti GroupBrass TyphoonDouble DragonBlackfly

Top techniques

All other tracked techniques

T1003.001 · LSASS MemoryT1003.002 · Security Account ManagerT1003.003 · NTDST1005 · Data from Local SystemT1008 · Fallback ChannelsT1012 · Query RegistryT1014 · RootkitT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027.002 · Software PackingT1030 · Data Transfer Size LimitsT1033 · System Owner/User DiscoveryT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1037 · Boot or Logon Initialization ScriptsT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.004 · Unix ShellT1059.005 · Visual BasicT1069 · Permission Groups DiscoveryT1070.003 · Clear Command HistoryT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.002 · File Transfer ProtocolsT1071.004 · DNST1078 · Valid AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1090 · ProxyT1098.007 · Additional Local or Domain GroupsT1102.001 · Dead Drop ResolverT1104 · Multi-Stage ChannelsT1105 · Ingress Tool TransferT1110 · Brute ForceT1112 · Modify RegistryT1127.001 · MSBuildT1133 · External Remote ServicesT1135 · Network Share DiscoveryT1136.001 · Local AccountT1197 · BITS JobsT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.003 · Code RepositoriesT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1218.011 · Rundll32T1480.001 · Environmental KeyingT1484.001 · Group Policy ModificationT1486 · Data Encrypted for ImpactT1496.001 · Compute HijackingT1542.003 · BootkitT1543.003 · Windows ServiceT1546.008 · Accessibility FeaturesT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1574.006 · Dynamic Linker HijackingT1583.001 · DomainsT1588.002 · ToolT1595.002 · Vulnerability ScanningT1595.003 · Wordlist ScanningT1596.005 · Scan DatabasesT1599 · Network Boundary BridgingT1684.001 · ImpersonationT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event Logs

Detection use cases (26)

APT41 (Wicked Panda/Winnti) DLL sideloading via signed third-party binary in user-writable path AI · profile SΣDD APT41 (Brass Typhoon) web-shell-driven recon chain from IIS/Tomcat after public-facing exploit AI · profile SΣDD PlugX phishing lure — 'Meeting Invitation' email linking to gesecole.net ZIP Bespoke Renamed MSBuild.exe executing inline .csproj from user-writable path Bespoke PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ Bespoke PlugX persistence — Run key 'G DATA' pointing to C:\Users\Public\GDatas\Avk.exe Bespoke PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Trusted vendor binary / installer launching unusual children Internal Network connections to article IPs / domains Internal File hash IOCs — endpoint file/process match Internal 1Password failed sign-in burst MITRE match 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (5)

decoorat.net decoraat.net gesecole.net onedow.gesecole.net onedown.gesecole.net