logo

China-Backed APT41 Cyberattack Surfaces in Africa

ID: 40c030ca-e3f4-5663-8a4f-18254200c847

STIX ID: report--40c030ca-e3f4-5663-8a4f-18254200c847

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-07-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky researchers documented an APT41 campaign against a government IT services provider in Africa in which attackers used both custom and public tools—Impacket (WmiExec/Atexec), Cobalt Strike, Mimikatz, Pillager, RawCopy, and Neo-reGeorg—to harvest credentials and exfiltrate data; the adversary embedded victim-specific service names/IPs and even used a compromised internal SharePoint server as a C2 to improve persistence and evade detection, illustrating high sophistication and adaptability amid rising regional cybercrime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.