APT41
Essential information
- Confidence
- 100/100
- Published
- 16/12/2025 19:39
- Modified
- 27/03/2026 01:14
- Updated at
- 27/03/2026 01:14
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Resource level
- —
- Primary motivation
- —
- Related entities
- 10 reports, 113 attack patterns (mitre), 35 malware, 21 sectors, 16 countries, 100 indicators, 6 vulnerabilities (cve), 10 tool
Aliases
Wicked Panda Brass Typhoon BARIUM
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (10)
-
4 CVEs 1 MITRE 2 Malwares 7 Observables 1 APT
-
4 Malwares 1 APT
-
14 MITREs 3 Malwares 10 Observables 1 APT
-
5 MITREs 5 Malwares 6 Observables 1 APT
-
20 MITREs 2 Malwares 2 Observables 1 APT
-
6 MITREs 8 Observables 1 APT
-
9 MITREs 9 Observables 1 APT
-
1 CVE 12 MITREs 4 Malwares 13 Observables 1 APT
-
7 MITREs 2 Malwares 3 Observables 1 APT
-
6 MITREs 2 Malwares 1 Observable 1 APT
Attack patterns (MITRE) (113)
-
T1036.003 usesRename Legitimate Utilities MITRE
-
T1195 usesSupply Chain Compromise MITRE
-
T1195.002 usesCompromise Software Supply Chain MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1550 usesUse Alternate Authentication Material MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1071.004 usesDNS MITRE
-
T1543.003 usesWindows Service MITRE
-
Compute Hijacking uses
-
T1595 usesActive Scanning MITRE
-
T1027.001 usesBinary Padding MITRE
-
T1602 MITRE
Malware (35)
-
MOPSLED usesFamily
-
Deed RAT usesFamily
-
Mydoor usesFamily
-
APT17 uses
-
KEYPLUG uses
-
China Chopper usesFamily
-
ShadowPad - S0596 usesFamily
-
DUSTPAN uses
-
MESSAGETAP uses
-
Derusbi uses
-
Dcsync usesFamily
-
PLUSDROP usesFamily
Sectors (21)
-
Sports targets
-
Defense ministries (including the military) targets
-
Finance targets
-
Road transport targets
-
Political parties targets
-
Telecommunications targets
-
Energy targets
-
Education targets
-
Chemical targets
-
Manufacturing targets
-
Healthcare targets
-
Transportation targets
Countries (16)
-
Brunei Darussalam targets
-
Central African Republic targets
-
United Arab Emirates targets
-
Ireland targets
-
Malaysia targets
-
India targets
-
Germany targets
-
Philippines targets
-
Mongolia targets
-
Viet Nam targets
-
Taiwan targets
-
Hong Kong targets
Indicators (100)
-
ns1.extrsports.rurelated -
151257e9dfda476cdafd9983266ad3255104d72a66f9265caa8417a5fe1df5d7related -
visualstudio-microsoft.comrelated -
c840e3cae2d280ff0b36eec2bf86ad35051906e484904136f0e478aa423d7744related -
http://ns1.extrsports.ru:443related -
51ffcff8367b5723d62b3e3108e38fb7cbf36354e0e520e7df7c8a4f52645c4drelated -
f040a173b954cdeadede3203a2021093b0458ed23727f849fc4c2676c67e25dbrelated -
99a0b424bb3a6bbf60e972fd82c514fd971a948f9cedf3b9dc6b033117ecb106related -
ns1.s3-azure.comrelated -
ff4c2a91a97859de316b434c8d0cd5a31acb82be8c62b2df6e78c47f85e57740related -
d62596889938442c34f9132c9587d1f35329925e011465c48c94aa4657c056c7related -
s3-azure.comrelated
Vulnerabilities (CVE) (6)
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code …
- Published
- 02/06/2022
- Modified
- 27/05/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a …
- Published
- 05/08/2024
- Modified
- 21/12/2025
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 12/12/2017
- Modified
- 22/04/2026
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to …
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 15/09/2017
- Modified
- 22/04/2026
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
Tool (10)
-
netstat usesThe MITRE Corporation Confidence 100
[netstat](https://attack.mitre.org/software/S0104) is an operating system utility that displays active TCP connections, listening ports, and network statistics. (Citation: TechNet Netstat)
-
pwdump usesThe MITRE Corporation Confidence 100
[pwdump](https://attack.mitre.org/software/S0006) is a credential dumper. (Citation: Wikipedia pwdump)
-
BITSAdmin usesThe MITRE Corporation Confidence 100
[BITSAdmin](https://attack.mitre.org/software/S0190) is a command line tool used to create and manage [BITS Jobs](https://attack.mitre.org/techniques/T1197). (Citation: Microsoft BITSAdmin)
-
PowerSploit usesThe MITRE Corporation Confidence 100
[PowerSploit](https://attack.mitre.org/software/S0194) is an open source, offensive security framework comprised of [PowerShell](https://attack.mitre.org/techniques/T1059/001) modules and scripts that perform a wide range of tasks related to penetration testing such as code…
-
Empire usesThe MITRE Corporation Confidence 100
[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents…
-
Impacket usesThe MITRE Corporation Confidence 100
[Impacket](https://attack.mitre.org/software/S0357) is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. [Impacket](https://attack.mitre.org/software/S0357) contains several tools for remote service execution, Kerberos manipulation,…
-
ftp usesThe MITRE Corporation Confidence 100
[ftp](https://attack.mitre.org/software/S0095) is a utility commonly available with operating systems to transfer information over the File Transfer Protocol (FTP). Adversaries can use it to transfer other tools onto a…
-
Ping usesThe MITRE Corporation Confidence 100
[Ping](https://attack.mitre.org/software/S0097) is an operating system utility commonly used to troubleshoot and verify network connections. (Citation: TechNet Ping)
-
Mimikatz usesThe MITRE Corporation Confidence 100
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of…
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…