logo

China's APT41 crew adds a stealthy malware loader and fresh backdoor to its toolbox

ID: 20f9a8f9-a775-5e39-936b-7beb435eb458

STIX ID: report--20f9a8f9-a775-5e39-936b-7beb435eb458

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-07-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Zscaler ThreatLabz researchers report that Chinese state-linked APT41 has very likely added a C-based shellcode loader called DodgeBox and a backdoor named MoonWalk to its toolkit; DodgeBox performs environment checks, disables protections (e.g., CFG), uses salted FNV1a hashes and AES-CFB for configuration, and decrypts and drops MoonWalk which uses Google Drive for C2, with observed targeting in Southeast Asia and medium-confidence attribution to APT41.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.