🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
APT41

/actor/apt41/  ·  1 intel report

Year Established
2012
Attribution
China (MSS)
Motivation
Espionage, Financial
Modus Operandi (MO)
Dual-track espionage and financial crime, supply chain attacks, zero-day exploitation, video game industry targeting
Primary Aliases
Double Dragon, Winnti Group, Barium, Earth Baku, Bronze Atlas

APT41, also known as Double Dragon, is a uniquely dual-purpose Chinese state-sponsored threat actor attributed to the Ministry of State Security (MSS). Unlike most nation-state APT groups that maintain strict separation between espionage and criminal activities, APT41 is exceptional in conducting both state-directed cyber espionage campaigns and financially motivated cybercrime operations, often simultaneously and using overlapping infrastructure.

On the espionage front, APT41 has conducted extensive campaigns targeting healthcare organisations, pharmaceutical companies, defence contractors, telecommunications providers, and government agencies. Their targeting priorities closely mirror Chinese state-sponsored industrial policy objectives.

Simultaneously, APT41 members have pursued personal financial enrichment through campaigns targeting the video game industry, stealing in-game currencies and virtual items for resale, conducting supply chain attacks to embed malware in legitimate software distributions, and deploying ransomware against non-strategic targets. In 2020, the US Department of Justice indicted five Chinese nationals associated with APT41 for these activities.

APT41's technical capabilities are among the most advanced of any tracked threat actor, encompassing a broad zero-day exploit inventory, sophisticated custom malware platforms including HIGHNOON, POISONPLUG, and DUSTPAN, and extensive supply chain compromise capabilities demonstrated most notably through the 2020 compromise of the ASUS Live Update utility and CCleaner software, which distributed backdoored updates to millions of users worldwide.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (1)

> cd ../articles