logo

APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor

ID: 369209f9-dbb6-53fe-b817-b90d6789707b

STIX ID: report--369209f9-dbb6-53fe-b817-b90d6789707b

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-13

Date Updated: 2026-04-14

...
...

APT41, a China-backed threat actor, is using a newly observed zero-detection ELF backdoor to target Linux cloud workloads across AWS, Google Cloud, Microsoft Azure, and Alibaba Cloud. The backdoor uses SMTP (port 25) for covert command-and-control, harvests cloud provider credentials and metadata, and leverages typosquatting to evade detection and attribution, creating a high-risk campaign against cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.